Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16841ECB920962137452B24E3A17B336FB1F7C70BEE43254156FC83D547D5D88ED1521A |
|
CONTENT
ssdeep
|
48:IfNmTNM1cOCUbhLGiB56VrCxPFk6ImbJC5clzD:Ij15L56ZCbxzJC5cJD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f0f00f0ff0f0f00f |
|
VISUAL
aHash
|
0000c0c0c0c00000 |
|
VISUAL
dHash
|
0060909080804000 |
|
VISUAL
wHash
|
ff0181e1e1c181ff |
|
VISUAL
colorHash
|
38000000038 |
|
VISUAL
cropResistant
|
0060909080804000 |
• Ameaça: Golpe de drenagem de carteira cripto
• Alvo: Usuários de criptomoedas
• Método: Conexão a dApp maliciosa
• Exfil: Conteúdo da carteira
• Indicadores: TLD de alto risco, marketing cripto agressivo
• Risco: Alto
The site likely prompts the user to connect a wallet (MetaMask/TrustWallet), then executes malicious smart contract calls to drain funds.
Uses 'staking' bait to trick users into interacting with a malicious dapp.