Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C4421E343080BA7790C7D2E2EB7567AFB7D0C24ACA2B970AA2F8C3595FDAC45CD51254 |
|
CONTENT
ssdeep
|
192:Lm7b9KrYa0aeX3d/fqQXyBnx5Q8QD7bpqoU:Lm/9OYa0b5U |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3343cb2b6e1c396 |
|
VISUAL
aHash
|
660070607c7c70f0 |
|
VISUAL
dHash
|
d430c0c4ccc8c060 |
|
VISUAL
wHash
|
661870707e7cf8f0 |
|
VISUAL
colorHash
|
38001000180 |
|
VISUAL
cropResistant
|
d430c0c4ccc8c060 |
• Threat: Cryptocurrency Phishing/Wallet Drainer
• Target: Web3 users
• Method: Malicious dApp interface
• Exfil: Wallet approval/signing
• Indicators: Obfuscated JS, suspicious domain, fake metrics
• Risk: Critical
Prompts user to connect Web3 wallet via a malicious bridge interface to trigger signature requests that drain tokens.
Attempts to gain session authorization for the user's wallet.