Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D631EFF1B09B94231232C1C2A592FB6236D3044DC4C566E11BFE53E896E5C5BF95B419 |
|
CONTENT
ssdeep
|
24:hR/C/2N/+TN/0AKZh/7k5qliZZb+5RHI1HXfaXdC+ihdrOdky:TnNmTNMdpWqliZGxEHXCXdC+ihdrOdky |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc3331cece6c31 |
|
VISUAL
aHash
|
8008183c18180000 |
|
VISUAL
dHash
|
2a90706130322913 |
|
VISUAL
wHash
|
ff3c183c18191b1b |
|
VISUAL
colorHash
|
38000e00000 |
|
VISUAL
cropResistant
|
2a90706130322913 |
• Threat: Crypto Airdrop Scam
• Target: Qubetics Investors
• Method: Malicious Token Claim
• Exfil: Wallet Drainer Interaction
• Indicators: Obfuscated JS, Urgency tactics
• Risk: Critical
The site uses a malicious script to prompt users to connect a Web3 wallet (e.g., MetaMask), subsequently prompting for transactions that drain assets.
Luring users with fake 'reborn' status to claim nonexistent tokens.