Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10C728470A4A2583F912B5AC1F5B07BAE60EAF30EDD5B0A14D3FC13EA5FD6C94E805125 |
|
CONTENT
ssdeep
|
384:WCzJzIOGcSToKTgnSwSSJo0JGe78yNKQl5HdSNSSLY/r9hezi1m2N1:tzJzI3cMfsnTS6FA8X4sRduSm6BgQj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
993476e2891fc8cb |
|
VISUAL
aHash
|
0000181818180000 |
|
VISUAL
dHash
|
bc8cb2b2b2b24c31 |
|
VISUAL
wHash
|
04c7181a7f18bdbd |
|
VISUAL
colorHash
|
30c000000c0 |
|
VISUAL
cropResistant
|
845d79767b193586,bc8cb2b2b2b24c31 |
• Ameaça: Phishing
• Alvo: Usuários de carteiras criptográficas
• Método: Impersonação e coleta de credenciais
• Exfil: wss://relay.walletconnect.org (potencial)
• Indicadores: Logotipos de carteiras, interface baseada em formulários, javascript ofuscado.
• Risco: ALTO
The site uses the logos and UI of legitimate wallets to trick users into connecting their wallets, likely requesting a seed phrase or private key after.
Pages with identical visual appearance (based on perceptual hash)