Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17373AC7340C698FF04E2A2C05771172A62A5B3A5FA4B46075BF8870B9F8BF65CD21D36 |
|
CONTENT
ssdeep
|
384:+vWU6WeNBXELiy/Y+nPacLhyV+yV7vGHpLhS5yN6dCgNBXELiy/Y+nPacLhyV+yh:+3BwZELk+Cuhysye9vmZELk+CuhysyAE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92926d6969646d6d |
|
VISUAL
aHash
|
000e6e0e04000000 |
|
VISUAL
dHash
|
99ccec8c29020800 |
|
VISUAL
wHash
|
6e7e7e7e0c000000 |
|
VISUAL
colorHash
|
38e00000008 |
|
VISUAL
cropResistant
|
a4245306e4e254c1,99ccec8c29020800 |
• Amenaza: Phishing
• Objetivo: Usuarios de criptomonedas
• Método: A través de un sitio web falso o comprometido.
• Exfil: Potencialmente credenciales financieras o acceso a billeteras.
• Indicadores: Alojamiento gratuito, contenido relacionado con cripto.
• Riesgo: Medio
The site likely attempts to harvest user credentials by presenting a fake interface that resembles a cryptocurrency platform or wallet.
Possibly attempts to entice users to download malicious software to steal wallet data.
```
┌─────────────────────────────────────────────────────────────────┐
│ VICTIM VISITS PHISHING SITE │
└─────────────────────────┬───────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ VICTIM INTERACTS WITH PAGE │
│ (Click links, download files, etc.) │
└─────────────────────────┬───────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ 🚨 ATTACK COMPLETE │
└─────────────────────────────────────────────────────────────────┘
```
```
┌─────────────────────────────────────────────────────────────────┐
│ VICTIM VISITS PHISHING SITE │
└─────────────────────────┬───────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ VICTIM INTERACTS WITH PAGE │
│ (Click links, download files, etc.) │
└─────────────────────────┬───────────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────────┐
│ 🚨 ATTACK COMPLETE │
└─────────────────────────────────────────────────────────────────┘
```
672b42829c51f52d769cd636.jsconnectWallet() (likely in ./app/ JS)signTransaction() (likely in ./app/ JS)sendTransaction() (likely in ./app/ JS)exfiltrate() (likely in ./app/ JS)Pages with identical visual appearance (based on perceptual hash)