Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1344155637602B42D7B1656F8D510B2ECC04243AECE50F884D9C089DD968ECCA5442BAE |
|
CONTENT
ssdeep
|
48:/WmfDhv5Qx/q0LkYX0Tl0n0w4Uzeu531hDEf6:ThiNL+Tq0mr5llEf6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
af2de0c90d2c2f0f |
|
VISUAL
aHash
|
bbff03133f83ffff |
|
VISUAL
dHash
|
528c6e6664232300 |
|
VISUAL
wHash
|
03e303033381fffe |
|
VISUAL
colorHash
|
07c000000c0 |
|
VISUAL
cropResistant
|
528c6e6664232300 |
The phishing site likely mimics MetaMask's wallet connection interface to trick users into approving malicious smart contract interactions. This allows attackers to request unlimited token approvals or drain assets via malicious dApp signatures.
The site includes forms to capture MetaMask seed phrases or private keys, enabling full account takeover and direct asset theft from the victim's wallet.
Highly obfuscated JavaScript file with 34 detected obfuscation techniques, likely containing credential harvesting logic.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain