Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16443646052335A6B02A383C1A6FA9F99D1C08350D3674B69F3FCC76FAECDC44AD55262 |
|
CONTENT
ssdeep
|
768:74eWEUSCw+ZO12WPj04X3M+0hsi6PEGgUf:c5EUSCw+ZO12WPjw6MGgUf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bad74d2c119594d5 |
|
VISUAL
aHash
|
02a4fe4cc5818100 |
|
VISUAL
dHash
|
36494c9919252712 |
|
VISUAL
wHash
|
02f5fecfcdc78100 |
|
VISUAL
colorHash
|
300000084c0 |
|
VISUAL
cropResistant
|
36494c9919252712 |
• Ameaça: Drenador de carteira de cripto
• Alvo: Usuários de carteiras de criptomoedas
• Método: Engenharia social via botão 'Connect Wallet'
• Exfil: Script de drenagem de carteira
• Indicadores: JS ofuscado, domínio suspeito
• Risco: Alto
The site mimics a DeFi interface to trick users into signing malicious transactions via their Web3 wallet, which then drains the wallet's contents.
Attempts to capture authorization tokens through prompt manipulation.
Pages with identical visual appearance (based on perceptual hash)