Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17C6223F19564E93704A7C1C2AAA65F2732F0454AE78B021643FD439C8FFAD51FE12E42 |
|
CONTENT
ssdeep
|
384:144AJl1rtmniS3Q73eDaotChC0zWUTQRDiEH0PFyaOoqyJC0bRe2+9S:144qjmniS3Q73eDaotChUwEmtde2+s |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c6c078f8d91f2725 |
|
VISUAL
aHash
|
e076367fff3c0000 |
|
VISUAL
dHash
|
808cece0c0e8e0f0 |
|
VISUAL
wHash
|
e076367fff7c0000 |
|
VISUAL
colorHash
|
09007000000 |
|
VISUAL
cropResistant
|
a3a63c898ce1f1f0,a7cecc70f0b0b0cc,808cece0c0e8e0f0 |
• Ameaça: Phishing de criptomoedas direcionado a usuários do Penguin
• Alvo: Usuários do Penguin
• Método: Site falso que afirma oferecer alocações seguras a membros de comunidades parceiras, projetado para roubar carteiras de criptomoedas.
• Exfil: Dados enviados para um local desconhecido
• Indicadores: Domínio muito novo, TLD .fun incomum, JavaScript ofuscado.
• Risco: ALTO - Potencial de roubo de carteiras de criptomoedas.
The phishing site likely prompts victims to connect their crypto wallets (e.g., Phantom, MetaMask) under the guise of 'securing allocations' or participating in a fake event. Once connected, the site may request token approvals or drain funds directly.
The site may collect personal details such as email addresses, phone numbers, or other sensitive information through deceptive forms or prompts, enabling further targeted attacks or identity theft.
Highly obfuscated JavaScript file with no legitimate context, likely containing malicious functionality for credential or wallet harvesting.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM VISITS FAKE CRYPTO PAGE │
│ - Phishing site mimics Penguin brand │
│ - Prompts wallet connection │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. WALLET CONNECTION REQUEST │
│ - Fake site requests wallet access │
│ - Victim approves malicious transaction │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. TRANSACTION SIGNING │
│ - Malicious payload signed by victim │
│ - Funds/tokens authorized for transfer │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Stolen data sent via HTTP POST │
│ - Standard form submission to attacker server │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM VISITS FAKE CRYPTO PAGE │
│ - Phishing site mimics Penguin brand │
│ - Prompts wallet connection │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. WALLET CONNECTION REQUEST │
│ - Fake site requests wallet access │
│ - Victim approves malicious transaction │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. TRANSACTION SIGNING │
│ - Malicious payload signed by victim │
│ - Funds/tokens authorized for transfer │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Stolen data sent via HTTP POST │
│ - Standard form submission to attacker server │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)