Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19F6396B223020B6E958783D4FB647B39A169834AD6575C8DF7F50053AF83E68FC563A0 |
|
CONTENT
ssdeep
|
768:mt7Qf3/XZobqHxZKlsUA2dFIfadIXBC2HHWCmHDWAYHAWDEHCWsBvfh1oqcU9o4d:mt7YtPKahxxeyKn/K8m |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c1ff1f32434c591 |
|
VISUAL
aHash
|
0000000000ffffff |
|
VISUAL
dHash
|
1a397135f9d02d9a |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
13c00000000 |
|
VISUAL
cropResistant
|
d8d430c22c2dd292,9a19393071353531 |
• Amenaza: Fraude de Inversión/Drenador de Crypto
• Objetivo: Usuarios de finanzas y cripto
• Método: Portal engañoso de alto rendimiento con conexión de billetera
• Exfil: Ofuscación de JavaScript
• Indicadores: Retornos financieros irreales e integración de wallet
• Riesgo: Alto
The site uses a 'Connect Wallet' button to trick users into signing malicious smart contracts to steal assets.
Promises high interest rates to entice users to deposit funds which are then stolen.