Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T114C16333D510E81A1FB6958CFAC0E19C9267D20BF63098C7B2C5615F6AC1EF598A137D |
|
CONTENT
ssdeep
|
96:uyC3aR1sYlYfMmORR1E8VConyro+ByOhl:umdCfMmUU8VCoUn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88dd227da8d5a2d5 |
|
VISUAL
aHash
|
ff187e1818000041 |
|
VISUAL
dHash
|
b271e8b2300e86c5 |
|
VISUAL
wHash
|
ff007e18bcff4041 |
|
VISUAL
colorHash
|
38006000080 |
|
VISUAL
cropResistant
|
b271e8b2300e86c5 |
โข Threat: Cryptocurrency exchange phishing
โข Target: Coinbase Pro users
โข Method: Imitates the Coinbase Pro trading platform
โข Exfil: Unknown, likely credential and API key harvesting
โข Indicators: Unofficial framer.media domain, "Made in Framer" watermark
โข Risk: HIGH - Potential for account takeover and fund theft
The phishing page mimics Coinbase's login interface to trick users into entering their wallet credentials. The harvested credentials are likely exfiltrated in real-time to an attacker-controlled server for immediate exploitation.
The presence of 'Deposit' and 'Withdraw' buttons suggests the page may simulate transactions to deceive users into believing they are interacting with a legitimate platform, potentially leading to further credential or seed phrase exposure.
Small JavaScript file with high obfuscation, likely used for credential harvesting.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING LURE โ
โ - Email/SMS with fake Coinbase link โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM VISITS FAKE COINBASE SITE โ
โ - Cloned Coinbase login page displayed โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL INPUT โ
โ - Victim enters wallet credentials โ
โ - Form appears identical to legitimate Coinbase โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. CREDENTIAL EXFILTRATION โ
โ - Data sent via HTTP POST to attacker-controlled โ
โ server (standard form submission) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING LURE โ
โ - Email/SMS with fake Coinbase link โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM VISITS FAKE COINBASE SITE โ
โ - Cloned Coinbase login page displayed โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL INPUT โ
โ - Victim enters wallet credentials โ
โ - Form appears identical to legitimate Coinbase โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. CREDENTIAL EXFILTRATION โ
โ - Data sent via HTTP POST to attacker-controlled โ
โ server (standard form submission) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain