Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16841ECB920962137452B24E3A17B336FB1F7C70BEE43254156FC83D547D5D88ED1521A |
|
CONTENT
ssdeep
|
48:IfNmTNM1cOCUbhLGiB56VrCxPFk6ImbJC5clzD:Ij15L56ZCbxzJC5cJD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f0f00f0ff0f0f00f |
|
VISUAL
aHash
|
0000c0c0c0c00000 |
|
VISUAL
dHash
|
0060909080804000 |
|
VISUAL
wHash
|
ff0181e1e1c181ff |
|
VISUAL
colorHash
|
38000000038 |
|
VISUAL
cropResistant
|
0060909080804000 |
• Amenaza: Estafa de drenaje de billetera cripto
• Objetivo: Usuarios de criptomonedas
• Método: Conexión a dApp maliciosa
• Exfil: Contenido de la billetera
• Indicadores: TLD de alto riesgo, marketing cripto agresivo
• Riesgo: Alto
The site likely prompts the user to connect a wallet (MetaMask/TrustWallet), then executes malicious smart contract calls to drain funds.
Uses 'staking' bait to trick users into interacting with a malicious dapp.