Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AEC283B06214513BA11796C7AF22773936FBB1FEE9BA0100E3FD46909BE4DD9AC23444 |
|
CONTENT
ssdeep
|
384:83WtqY+SAaudOgU74CyZdwq/e2oxRYXT+64ylFOU0KX2Cc8HYc1RcWc66hT:8YAaum/y7w32GRYXTrlFH0KvYwUT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92922d6de99696e2 |
|
VISUAL
aHash
|
02646c6c4000407e |
|
VISUAL
dHash
|
96cdcd8d9268d4d4 |
|
VISUAL
wHash
|
47447c7e60047e7e |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
e89862c4cda2e6e8,96cdcd8d9268d4d4 |
• Amenaza: Estafa de airdrop de criptomonedas suplantando a Ryanair
• Objetivo: Individuos interesados en Ryanair y criptomonedas
• Método: Airdrop falso para recopilar información o fondos del usuario
• Exfil: Probablemente recopilando información de billetera de criptomonedas o dirigiendo a los usuarios a sitios de phishing
• Indicadores: Dominio no oficial, dominio nuevo, promesas de criptomonedas e impersonación de marca
• Riesgo: ALTO - Potencial de pérdida financiera a través de estafa de criptomonedas
The campaign lures victims with fake crypto rewards, likely tricking them into connecting wallets (e.g., MetaMask, Phantom) to drain funds via malicious smart contract interactions or token approvals.
While no forms were detected, the presence of a Credential Harvester kit suggests potential hidden fields or dynamic form injection to capture login credentials or OTPs.
Contains obfuscated JavaScript with 38 detected obfuscation techniques, likely for evasion and malicious payload delivery.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE │
│ - Fake Ryanair crypto promotion email/link │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM LANDS ON FAKE RYANAIR PAGE │
│ - Mimics legitimate Ryanair site │
│ - Displays crypto investment scam │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. VICTIM ENTERS CRYPTO WALLET DETAILS │
│ - Fake form requests wallet credentials │
│ - May include "investment" amount fields │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Form submits via HTTP POST │
│ - Wallet details sent to attacker server │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE │
│ - Fake Ryanair crypto promotion email/link │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM LANDS ON FAKE RYANAIR PAGE │
│ - Mimics legitimate Ryanair site │
│ - Displays crypto investment scam │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. VICTIM ENTERS CRYPTO WALLET DETAILS │
│ - Fake form requests wallet credentials │
│ - May include "investment" amount fields │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Form submits via HTTP POST │
│ - Wallet details sent to attacker server │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)