Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AB6254B69102A93F11F3C1D2A621AB3F72E6914DDA4B0B0653FC4B2D4BC6DA0FC25599 |
|
CONTENT
ssdeep
|
192:wVsBilI0IINBXf3myiCBdtE5kMEzmc8T5c3/7MNR3PZR/37:usBgxII/3m70DE9zW3jA3PDj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c68cb8b086cfe1bc |
|
VISUAL
aHash
|
ff000074266000ff |
|
VISUAL
dHash
|
2f34cbc4c4cc2340 |
|
VISUAL
wHash
|
ff000076767700ff |
|
VISUAL
colorHash
|
30000e40000 |
|
VISUAL
cropResistant
|
c029292f2f2929c4,0000000000000000,4133c8c4cccd2340 |
• Amenaza: Drenador de billeteras cripto
• Objetivo: Usuarios de criptomonedas
• Método: Ingeniería social mediante herramienta de trading
• Exfil: Envío de formulario JS
• Indicadores: JS ofuscado, promesas de ganancias rápidas
• Riesgo: Pérdida financiera crítica
The site uses a deceptive interface to trick users into connecting their Web3 wallets. Once connected, malicious scripts attempt to prompt the user to sign a fraudulent transaction or approve token transfers.
Forms designed to capture wallet information or API keys under the guise of setting up an AI trading terminal.