Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F6C296B02264103BA11B96DB6F26277936FBB1FDD8BB1154D7FD0A90ABE5C88F813045 |
|
CONTENT
ssdeep
|
384:HWtqY+SAakFsiyteAG4UOOeAG4UOJWAU74CyZwQwq/V7/2o1RYXFFFCY01aVGux3:oAa4sko/y2Qwc7/2eRYXd0TYwKyhh0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92922d6de99296e3 |
|
VISUAL
aHash
|
03646c6c4000407e |
|
VISUAL
dHash
|
968dcd8d926cd4d4 |
|
VISUAL
wHash
|
4f447c7e60007e7e |
|
VISUAL
colorHash
|
38407000000 |
|
VISUAL
cropResistant
|
e8d8b2eccda2e6e8,968dcd8d926cd4d4 |
โข Threat: Cryptocurrency phishing scam
โข Target: Crypto enthusiasts and investors
โข Method: Fake airdrop promotion to steal user data
โข Exfil: Potential data exfiltration via obfuscated scripts
โข Indicators: Domain mismatch, urgency tactics, recent domain
โข Risk: HIGH - Potential for data theft and financial loss
The phishing site prompts users to connect their cryptocurrency wallets (e.g., MetaMask, Phantom) using buttons labeled 'Connect Wallet'. Once connected, the site likely requests token approvals or private key access to drain funds.
While no forms are visible, the presence of a Credential Harvester kit suggests hidden or dynamically loaded fields to capture login credentials or OTPs for account takeover.
Contains obfuscated JavaScript code likely used for credential harvesting and wallet connection.
Pages with identical visual appearance (based on perceptual hash)