Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A2F23AF56394A6B9B201C3E4D732663A739711FADE838310C3ED9B9C89D9C8EDC59841 |
|
CONTENT
ssdeep
|
768:CthXTRlXND9bVbv9OpTTRVPCMOXTcV/7s:+RFVr9OpvXCMOXTcV/7s |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b922c65dc9ca53ca |
|
VISUAL
aHash
|
7f070309090fffff |
|
VISUAL
dHash
|
ae1edb7b1b1ac8c0 |
|
VISUAL
wHash
|
3f070101090effff |
|
VISUAL
colorHash
|
160001c0001 |
|
VISUAL
cropResistant
|
ae0e5f5b9b731b1a,8080c0c08064e2e0,2e1e5fdb7b531a1a |
The phishing kit likely tricks users into connecting their cryptocurrency wallets (e.g., MetaMask, Phantom) to a malicious smart contract. Once connected, the kit requests token approvals or directly initiates unauthorized transactions to drain assets.
The kit may capture OpenSeaPro login credentials through fake login forms or overlays, enabling account takeover and further exploitation of stored payment methods or NFT assets.
Obfuscated JavaScript file with no legitimate functionality detected, likely used for malicious wallet interactions or credential harvesting.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM TARGETED WITH FAKE OPENSEAPRO LINK │
│ - Phishing email/SMS directs to malicious site │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE WALLET CONNECTION PROMPT │
│ - Malicious site requests crypto wallet access │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. VICTIM APPROVES MALICIOUS TRANSACTION │
│ - Fake "sign" request drains wallet assets │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. WALLET DRAINED & DATA EXFILTRATED │
│ - Transaction details sent via HTTP POST │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM TARGETED WITH FAKE OPENSEAPRO LINK │
│ - Phishing email/SMS directs to malicious site │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE WALLET CONNECTION PROMPT │
│ - Malicious site requests crypto wallet access │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. VICTIM APPROVES MALICIOUS TRANSACTION │
│ - Fake "sign" request drains wallet assets │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. WALLET DRAINED & DATA EXFILTRATED │
│ - Transaction details sent via HTTP POST │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain