Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T114C16333D510E81A1FB6958CFAC0E19C9267D20BF63098C7B2C5615F6AC1EF598A137D |
|
CONTENT
ssdeep
|
96:uyC3aR1sYlYfMmORR1E8VConyro+ByOhl:umdCfMmUU8VCoUn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88dd227da8d5a2d5 |
|
VISUAL
aHash
|
ff187e1818000041 |
|
VISUAL
dHash
|
b271e8b2300e86c5 |
|
VISUAL
wHash
|
ff007e18bcff4041 |
|
VISUAL
colorHash
|
38006000080 |
|
VISUAL
cropResistant
|
b271e8b2300e86c5 |
• Ameaça: Phishing de plataforma de criptomoeda
• Alvo: Usuários do Coinbase
• Método: Interface falsa de negociação do Coinbase Pro
• Exfil: Desconhecido, provavelmente coleta de credenciais
• Indicadores: Domínio não oficial, hospedagem framer.media, JavaScript ofuscado
• Risco: ALTO - Potencial para roubo de credenciais e comprometimento da conta
Targets Coinbase users by mimicking the official wallet connection interface. The phishing page likely prompts victims to connect their cryptocurrency wallet (e.g., MetaMask, Coinbase Wallet) to a malicious smart contract, enabling unauthorized token approvals or direct asset theft.
Although no visible form fields are present, the Credential Harvester kit type suggests the page may dynamically capture login credentials (email, password, 2FA codes) via hidden or injected forms, transmitting them to an attacker-controlled server.
Small, obfuscated JavaScript file likely containing credential harvesting or wallet hijacking logic.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM TARGETED WITH PHISHING LINK │
│ - Fake Coinbase page delivered via email/message │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM CONNECTS WALLET TO FAKE SITE │
│ - Fake "Connect Wallet" prompt displayed │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. WALLET CONNECTION HIJACKED │
│ - Attacker intercepts connection request │
│ - Gains access to wallet session │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. TRANSACTION REQUEST SENT │
│ - Fake transaction prompt appears │
│ - Victim unknowingly approves malicious transfer │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATION │
│ - Stolen credentials/wallet data sent via HTTP POST │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM TARGETED WITH PHISHING LINK │
│ - Fake Coinbase page delivered via email/message │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM CONNECTS WALLET TO FAKE SITE │
│ - Fake "Connect Wallet" prompt displayed │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. WALLET CONNECTION HIJACKED │
│ - Attacker intercepts connection request │
│ - Gains access to wallet session │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. TRANSACTION REQUEST SENT │
│ - Fake transaction prompt appears │
│ - Victim unknowingly approves malicious transfer │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATION │
│ - Stolen credentials/wallet data sent via HTTP POST │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain