Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AEE3B9362342242E235F07D0B6E0EF6D52ABE245CE578D6E73EC24B19FC9DD09DA5188 |
|
CONTENT
ssdeep
|
1536:9d7Owq8T9LF5FXN7jBQ+Cwrayj/z//vW/vs/4hOPJCCcvLSyt73:CwthFXpayvvs5mXcjSyt7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dffd66da18259880 |
|
VISUAL
aHash
|
80809c9c9c9c8080 |
|
VISUAL
dHash
|
2228383838390638 |
|
VISUAL
wHash
|
c0dcfe9f9cbcc080 |
|
VISUAL
colorHash
|
38000430000 |
|
VISUAL
cropResistant
|
00047ab2b2320400,2228383838390638 |
⢠Threat: Cryptocurrency Phishing (Wallet Drainer)
⢠Target: Solstice Finance users
⢠Method: Typosquatting/Airdrop scam
⢠Exfil: Wallet approval/signing
⢠Indicators: Obfuscated JS code, typosquatted domain
⢠Risk: Critical
The site prompts users to connect their Web3 wallet. Once connected, malicious scripts request permissions to drain tokens or NFTs.
Uses a deceptive URL to trick users into thinking they are on the official financial platform.