Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B003A470D1492926B177D4D1E471936FB2A1C34CDB930B5897EC936AB6CACB1FE221C8 |
|
CONTENT
ssdeep
|
768:dKUS33gQS1CcuWCvQODcuWCvQOqzebbiGSMJaUVniJI3OASAIIzCj/F6byyY0fKW:03gQS1CcuWCvQODcuWCvQOxtW+eASAI+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc993366cc996666 |
|
VISUAL
aHash
|
0000181818000000 |
|
VISUAL
dHash
|
0008303030080000 |
|
VISUAL
wHash
|
bd5abd3cbd42a500 |
|
VISUAL
colorHash
|
38200040006 |
|
VISUAL
cropResistant
|
0008303030080000 |
• Amenaza: Drenador de criptomonedas
• Objetivo: Usuarios de Pump.fun
• Método: Conexión a dApp maliciosa
• Exfil: Captura de datos vía WebSocket
• Indicadores: JS ofuscado, dominio sospechoso
• Riesgo: Crítico
The site uses social engineering to prompt a wallet connection, subsequently executing malicious transactions to empty assets.
Uses WebSockets to monitor session activity and extract metadata.
Pages with identical visual appearance (based on perceptual hash)