Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11A321360F0B4AB3B51E3D5E2B771376A5D9FC22AC46BD402BEE5C28B4BC9D10CD09256 |
|
CONTENT
ssdeep
|
192:be6sjqspTvsNdcXACAi/L9/7gCY6kRzVVBsnH:ZRATvsLcXACAi/L9/7TY6kRzVXSH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c98c36b1cccdc1b6 |
|
VISUAL
aHash
|
ff04787878781818 |
|
VISUAL
dHash
|
f278f2d2c2d2d2f0 |
|
VISUAL
wHash
|
ff38787878781838 |
|
VISUAL
colorHash
|
000010001c0 |
|
VISUAL
cropResistant
|
6b695332ada6f5b5,f278f2d2c2d2d2f0 |
โข Threat: Phishing
โข Target: Cryptocurrency wallets
โข Method: Impersonation and wallet connection
โข Exfil: Wallet information, possibly private keys
โข Indicators: Free hosting, obfuscation, wallet sync request.
โข Risk: High
The site appears to be impersonating a wallet or a service related to wallets, designed to trick users into connecting their wallets, potentially exposing their assets or credentials.
Obfuscated Javascript is present, likely to perform malicious actions. This could involve stealing information from the user's wallet or attempting to redirect funds.
User fills <input name='wallet'> โ sendData() โ fetch('https://dappconnecthub.pages.dev/api/exfiltrate') โ credentials sent to server
User fills <input name='wallet'> โ sendData() โ fetch('https://dappconnecthub.pages.dev/api/exfiltrate') โ credentials sent to server
index-3a7670c9.jssendDatasubmitFormPages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain