Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C4421E343080BA7790C7D2E2EB7567AFB7D0C24ACA2B970AA2F8C3595FDAC45CD51254 |
|
CONTENT
ssdeep
|
192:Lm7b9KrYa0aeX3d/fqQXyBnx5Q8QD7bpqoU:Lm/9OYa0b5U |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3343cb2b6e1c396 |
|
VISUAL
aHash
|
660070607c7c70f0 |
|
VISUAL
dHash
|
d430c0c4ccc8c060 |
|
VISUAL
wHash
|
661870707e7cf8f0 |
|
VISUAL
colorHash
|
38001000180 |
|
VISUAL
cropResistant
|
d430c0c4ccc8c060 |
• Amenaza: Phishing de criptomonedas/Drenador de billeteras
• Objetivo: Usuarios de Web3
• Método: Interfaz de dApp maliciosa
• Exfil: Aprobación/firma de billetera
• Indicadores: JS ofuscado, dominio sospechoso, métricas falsas
• Riesgo: Crítico
Prompts user to connect Web3 wallet via a malicious bridge interface to trigger signature requests that drain tokens.
Attempts to gain session authorization for the user's wallet.