Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17CF37DF5325CB3B3165303E66076110732BA207FB9068D60E3D4DECAA7BACD9942BD95 |
|
CONTENT
ssdeep
|
1536:aOY/1RY/1e03hUR/+HALGqqLii6b1hJElUuRNka2wblHbJLwLIz9GguGOjjRnY:obD8rX2wd9W/guGO+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b1644c9b9bcc3371 |
|
VISUAL
aHash
|
98c0c3ffe7efffc3 |
|
VISUAL
dHash
|
299696e4cdcd372b |
|
VISUAL
wHash
|
000042e7e7effbc3 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
299696e4cdcd372b |
• Amenaza: Phishing
• Objetivo: Carteras de criptomonedas
• Método: Engaño, a través de un sitio web sospechoso que afirma brindar seguridad para las carteras de criptomonedas.
• Exfil: wss://relay.walletconnect.org
• Indicadores: Javascript ofuscado, dominio sospechoso.
• Riesgo: Alto
The site uses a landing page with claims to protect wallets and encourages the user to 'Check Your Wallet'. It probably redirects to a form to enter credentials or it may involve a malware download
The website tries to take advantage of user fears of illicit funds frozen.
Pages with identical visual appearance (based on perceptual hash)