Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T114C16333D510E81A1FB6958CFAC0E19C9267D20BF63098C7B2C5615F6AC1EF598A137D |
|
CONTENT
ssdeep
|
96:uyC3aR1sYlYfMmORR1E8VConyro+ByOhl:umdCfMmUU8VCoUn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88dd227da8d5a2d5 |
|
VISUAL
aHash
|
ff187e1818000041 |
|
VISUAL
dHash
|
b271e8b2300e86c5 |
|
VISUAL
wHash
|
ff007e18bcff4041 |
|
VISUAL
colorHash
|
38006000080 |
|
VISUAL
cropResistant
|
b271e8b2300e86c5 |
โข Threat: Cryptocurrency platform phishing
โข Target: Coinbase users
โข Method: Fake Coinbase Pro trading interface
โข Exfil: Unknown, likely credential harvesting
โข Indicators: Unofficial domain, framer.media hosting, obfuscated JavaScript
โข Risk: HIGH - Potential for credential theft and account compromise
Targets Coinbase users by mimicking the official wallet connection interface. The phishing page likely prompts victims to connect their cryptocurrency wallet (e.g., MetaMask, Coinbase Wallet) to a malicious smart contract, enabling unauthorized token approvals or direct asset theft.
Although no visible form fields are present, the Credential Harvester kit type suggests the page may dynamically capture login credentials (email, password, 2FA codes) via hidden or injected forms, transmitting them to an attacker-controlled server.
Small, obfuscated JavaScript file likely containing credential harvesting or wallet hijacking logic.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM TARGETED WITH PHISHING LINK โ
โ - Fake Coinbase page delivered via email/message โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM CONNECTS WALLET TO FAKE SITE โ
โ - Fake "Connect Wallet" prompt displayed โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. WALLET CONNECTION HIJACKED โ
โ - Attacker intercepts connection request โ
โ - Gains access to wallet session โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. TRANSACTION REQUEST SENT โ
โ - Fake transaction prompt appears โ
โ - Victim unknowingly approves malicious transfer โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 5. DATA EXFILTRATION โ
โ - Stolen credentials/wallet data sent via HTTP POST โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM TARGETED WITH PHISHING LINK โ
โ - Fake Coinbase page delivered via email/message โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM CONNECTS WALLET TO FAKE SITE โ
โ - Fake "Connect Wallet" prompt displayed โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. WALLET CONNECTION HIJACKED โ
โ - Attacker intercepts connection request โ
โ - Gains access to wallet session โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. TRANSACTION REQUEST SENT โ
โ - Fake transaction prompt appears โ
โ - Victim unknowingly approves malicious transfer โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 5. DATA EXFILTRATION โ
โ - Stolen credentials/wallet data sent via HTTP POST โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain