Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AEC283B06214513BA11796C7AF22773936FBB1FEE9BA0100E3FD46909BE4DD9AC23444 |
|
CONTENT
ssdeep
|
384:83WtqY+SAaudOgU74CyZdwq/e2oxRYXT+64ylFOU0KX2Cc8HYc1RcWc66hT:8YAaum/y7w32GRYXTrlFH0KvYwUT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92922d6de99696e2 |
|
VISUAL
aHash
|
02646c6c4000407e |
|
VISUAL
dHash
|
96cdcd8d9268d4d4 |
|
VISUAL
wHash
|
47447c7e60047e7e |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
e89862c4cda2e6e8,96cdcd8d9268d4d4 |
โข Threat: Cryptocurrency airdrop scam impersonating Ryanair
โข Target: Individuals interested in Ryanair and cryptocurrency
โข Method: Fake airdrop to collect user information or funds
โข Exfil: Likely collecting cryptocurrency wallet information or directing users to phishing sites
โข Indicators: Unofficial domain, new domain, crypto promises, and brand impersonation
โข Risk: HIGH - Potential for financial loss through crypto scam
The campaign lures victims with fake crypto rewards, likely tricking them into connecting wallets (e.g., MetaMask, Phantom) to drain funds via malicious smart contract interactions or token approvals.
While no forms were detected, the presence of a Credential Harvester kit suggests potential hidden fields or dynamic form injection to capture login credentials or OTPs.
Contains obfuscated JavaScript with 38 detected obfuscation techniques, likely for evasion and malicious payload delivery.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING LURE โ
โ - Fake Ryanair crypto promotion email/link โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM LANDS ON FAKE RYANAIR PAGE โ
โ - Mimics legitimate Ryanair site โ
โ - Displays crypto investment scam โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. VICTIM ENTERS CRYPTO WALLET DETAILS โ
โ - Fake form requests wallet credentials โ
โ - May include "investment" amount fields โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Form submits via HTTP POST โ
โ - Wallet details sent to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING LURE โ
โ - Fake Ryanair crypto promotion email/link โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM LANDS ON FAKE RYANAIR PAGE โ
โ - Mimics legitimate Ryanair site โ
โ - Displays crypto investment scam โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. VICTIM ENTERS CRYPTO WALLET DETAILS โ
โ - Fake form requests wallet credentials โ
โ - May include "investment" amount fields โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Form submits via HTTP POST โ
โ - Wallet details sent to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)