Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17C6223F19564E93704A7C1C2AAA65F2732F0454AE78B021643FD439C8FFAD51FE12E42 |
|
CONTENT
ssdeep
|
384:144AJl1rtmniS3Q73eDaotChC0zWUTQRDiEH0PFyaOoqyJC0bRe2+9S:144qjmniS3Q73eDaotChUwEmtde2+s |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c6c078f8d91f2725 |
|
VISUAL
aHash
|
e076367fff3c0000 |
|
VISUAL
dHash
|
808cece0c0e8e0f0 |
|
VISUAL
wHash
|
e076367fff7c0000 |
|
VISUAL
colorHash
|
09007000000 |
|
VISUAL
cropResistant
|
a3a63c898ce1f1f0,a7cecc70f0b0b0cc,808cece0c0e8e0f0 |
โข Threat: Cryptocurrency phishing targeting Penguin users
โข Target: Penguin users
โข Method: Fake website claiming to offer secure allocations to members of partner communities, designed to steal crypto wallets.
โข Exfil: Data sent to unknown location
โข Indicators: Very new domain, unusual .fun TLD, obfuscated JavaScript.
โข Risk: HIGH - Potential for theft of cryptocurrency wallets.
The phishing site likely prompts victims to connect their crypto wallets (e.g., Phantom, MetaMask) under the guise of 'securing allocations' or participating in a fake event. Once connected, the site may request token approvals or drain funds directly.
The site may collect personal details such as email addresses, phone numbers, or other sensitive information through deceptive forms or prompts, enabling further targeted attacks or identity theft.
Highly obfuscated JavaScript file with no legitimate context, likely containing malicious functionality for credential or wallet harvesting.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM VISITS FAKE CRYPTO PAGE โ
โ - Phishing site mimics Penguin brand โ
โ - Prompts wallet connection โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. WALLET CONNECTION REQUEST โ
โ - Fake site requests wallet access โ
โ - Victim approves malicious transaction โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. TRANSACTION SIGNING โ
โ - Malicious payload signed by victim โ
โ - Funds/tokens authorized for transfer โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Stolen data sent via HTTP POST โ
โ - Standard form submission to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM VISITS FAKE CRYPTO PAGE โ
โ - Phishing site mimics Penguin brand โ
โ - Prompts wallet connection โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. WALLET CONNECTION REQUEST โ
โ - Fake site requests wallet access โ
โ - Victim approves malicious transaction โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. TRANSACTION SIGNING โ
โ - Malicious payload signed by victim โ
โ - Funds/tokens authorized for transfer โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Stolen data sent via HTTP POST โ
โ - Standard form submission to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)