Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T184E2636D1116247F6237C9E576207749E1A7A31CCF3B9D08B7F8422A7BDAC428EC2539 |
|
CONTENT
ssdeep
|
768:P9+C5oFe/13odaW72A0RvG0dAIpmp2pDpap3papIpypYpapvpWpIXHLL0lLL0EXP:P3J+AFAawg1UZUaMKUxAbb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ac19c1c34b6bd369 |
|
VISUAL
aHash
|
f99b8f9797f7f1f1 |
|
VISUAL
dHash
|
6b36372727052703 |
|
VISUAL
wHash
|
b98b838191f1f1f1 |
|
VISUAL
colorHash
|
070080001c0 |
|
VISUAL
cropResistant
|
6b36372727052703,0551a6d4d423d445,01100cb2b2320c20 |
• Amenaza: Phishing
• Objetivo: Usuarios de monederos de criptomonedas
• Método: Suplantación de identidad y recolección de datos
• Exfil: WebSockets de WalletConnect
• Indicadores: Coincidencia de dominio, envío de formulario, ofuscación.
• Riesgo: Moderado
The site impersonates a cryptocurrency wallet checker to collect information, likely email addresses. Users are encouraged to click a button, which would likely redirect to another page.
Email addresses harvested could be used to send out phishing emails with malicious links.
Pages with identical visual appearance (based on perceptual hash)