Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T114C16333D510E81A1FB6958CFAC0E19C9267D20BF63098C7B2C5615F6AC1EF598A137D |
|
CONTENT
ssdeep
|
96:uyC3aR1sYlYfMmORR1E8VConyro+ByOhl:umdCfMmUU8VCoUn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88dd227da8d5a2d5 |
|
VISUAL
aHash
|
ff187e1818000041 |
|
VISUAL
dHash
|
b271e8b2300e86c5 |
|
VISUAL
wHash
|
ff007e18bcff4041 |
|
VISUAL
colorHash
|
38006000080 |
|
VISUAL
cropResistant
|
b271e8b2300e86c5 |
• Amenaza: Suplantación de identidad de plataforma de criptomonedas
• Objetivo: Usuarios de Coinbase
• Método: Interfaz falsa de comercio de Coinbase Pro
• Exfil: Desconocido, probablemente recolección de credenciales
• Indicadores: Dominio no oficial, alojamiento en framer.media, JavaScript ofuscado
• Riesgo: ALTO - Potencial de robo de credenciales y compromiso de cuenta
Targets Coinbase users by mimicking the official wallet connection interface. The phishing page likely prompts victims to connect their cryptocurrency wallet (e.g., MetaMask, Coinbase Wallet) to a malicious smart contract, enabling unauthorized token approvals or direct asset theft.
Although no visible form fields are present, the Credential Harvester kit type suggests the page may dynamically capture login credentials (email, password, 2FA codes) via hidden or injected forms, transmitting them to an attacker-controlled server.
Small, obfuscated JavaScript file likely containing credential harvesting or wallet hijacking logic.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM TARGETED WITH PHISHING LINK │
│ - Fake Coinbase page delivered via email/message │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM CONNECTS WALLET TO FAKE SITE │
│ - Fake "Connect Wallet" prompt displayed │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. WALLET CONNECTION HIJACKED │
│ - Attacker intercepts connection request │
│ - Gains access to wallet session │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. TRANSACTION REQUEST SENT │
│ - Fake transaction prompt appears │
│ - Victim unknowingly approves malicious transfer │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATION │
│ - Stolen credentials/wallet data sent via HTTP POST │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM TARGETED WITH PHISHING LINK │
│ - Fake Coinbase page delivered via email/message │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM CONNECTS WALLET TO FAKE SITE │
│ - Fake "Connect Wallet" prompt displayed │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. WALLET CONNECTION HIJACKED │
│ - Attacker intercepts connection request │
│ - Gains access to wallet session │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. TRANSACTION REQUEST SENT │
│ - Fake transaction prompt appears │
│ - Victim unknowingly approves malicious transfer │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATION │
│ - Stolen credentials/wallet data sent via HTTP POST │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain