Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17C6223F19564E93704A7C1C2AAA65F2732F0454AE78B021643FD439C8FFAD51FE12E42 |
|
CONTENT
ssdeep
|
384:144AJl1rtmniS3Q73eDaotChC0zWUTQRDiEH0PFyaOoqyJC0bRe2+9S:144qjmniS3Q73eDaotChUwEmtde2+s |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c6c078f8d91f2725 |
|
VISUAL
aHash
|
e076367fff3c0000 |
|
VISUAL
dHash
|
808cece0c0e8e0f0 |
|
VISUAL
wHash
|
e076367fff7c0000 |
|
VISUAL
colorHash
|
09007000000 |
|
VISUAL
cropResistant
|
a3a63c898ce1f1f0,a7cecc70f0b0b0cc,808cece0c0e8e0f0 |
• Amenaza: Phishing de criptomonedas dirigido a usuarios de Penguin
• Objetivo: Usuarios de Penguin
• Método: Sitio web falso que afirma ofrecer asignaciones seguras a miembros de comunidades asociadas, diseñado para robar billeteras criptográficas.
• Exfil: Datos enviados a una ubicación desconocida
• Indicadores: Dominio muy nuevo, TLD .fun inusual, JavaScript ofuscado.
• Riesgo: ALTO - Potencial de robo de billeteras de criptomonedas.
The phishing site likely prompts victims to connect their crypto wallets (e.g., Phantom, MetaMask) under the guise of 'securing allocations' or participating in a fake event. Once connected, the site may request token approvals or drain funds directly.
The site may collect personal details such as email addresses, phone numbers, or other sensitive information through deceptive forms or prompts, enabling further targeted attacks or identity theft.
Highly obfuscated JavaScript file with no legitimate context, likely containing malicious functionality for credential or wallet harvesting.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM VISITS FAKE CRYPTO PAGE │
│ - Phishing site mimics Penguin brand │
│ - Prompts wallet connection │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. WALLET CONNECTION REQUEST │
│ - Fake site requests wallet access │
│ - Victim approves malicious transaction │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. TRANSACTION SIGNING │
│ - Malicious payload signed by victim │
│ - Funds/tokens authorized for transfer │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Stolen data sent via HTTP POST │
│ - Standard form submission to attacker server │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM VISITS FAKE CRYPTO PAGE │
│ - Phishing site mimics Penguin brand │
│ - Prompts wallet connection │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. WALLET CONNECTION REQUEST │
│ - Fake site requests wallet access │
│ - Victim approves malicious transaction │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. TRANSACTION SIGNING │
│ - Malicious payload signed by victim │
│ - Funds/tokens authorized for transfer │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Stolen data sent via HTTP POST │
│ - Standard form submission to attacker server │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)