Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17DB285B3A0C27D3702B7E1D296B6937B71D6814DC9774960A3FC83AD67C0D90A96A343 |
|
CONTENT
ssdeep
|
384:KhNw0503svrUUHTeAn/g8SD/6YmlNWJkz/Dwg8W3oFhrKNH3lJs54i:GSsQUHTXn/g8Y6YmHWmzbwghoFhrKNH4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8cab23ac8b8eae33 |
|
VISUAL
aHash
|
8100183c18181000 |
|
VISUAL
dHash
|
6310617032b03000 |
|
VISUAL
wHash
|
ff3c3c3c3c3c0000 |
|
VISUAL
colorHash
|
38000000e00 |
|
VISUAL
cropResistant
|
6310617032b03000 |
• Amenaza: Suplantación de identidad/Drenador de billeteras
• Objetivo: Usuarios de 1inch Network
• Método: Sitio de suplantación/Typosquatting
• Exfil: Script malicioso ofuscado
• Indicadores: Dominio no relacionado, dominio registrado hace 14 días
• Riesgo: Alto - Robo de fondos
The site uses a malicious 'Connect Wallet' button to trigger a Web3 interaction that asks the user to sign a malicious transaction, allowing the attacker to transfer tokens out of the user's wallet.
Hosting on a domain that appears semi-professional ('lifinity-dex') to deceive users into believing it is a legitimate decentralized exchange interface.
Pages with identical visual appearance (based on perceptual hash)