Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AEC283B06214513BA11796C7AF22773936FBB1FEE9BA0100E3FD46909BE4DD9AC23444 |
|
CONTENT
ssdeep
|
384:83WtqY+SAaudOgU74CyZdwq/e2oxRYXT+64ylFOU0KX2Cc8HYc1RcWc66hT:8YAaum/y7w32GRYXTrlFH0KvYwUT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92922d6de99696e2 |
|
VISUAL
aHash
|
02646c6c4000407e |
|
VISUAL
dHash
|
96cdcd8d9268d4d4 |
|
VISUAL
wHash
|
47447c7e60047e7e |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
e89862c4cda2e6e8,96cdcd8d9268d4d4 |
• Ameaça: Golpe de airdrop de criptomoedas se passando por Ryanair
• Alvo: Indivíduos interessados em Ryanair e criptomoedas
• Método: Airdrop falso para coletar informações ou fundos do usuário
• Exfil: Provavelmente coletando informações de carteira de criptomoedas ou direcionando usuários para sites de phishing
• Indicadores: Domínio não oficial, domínio novo, promessas de criptomoedas e representação de marca
• Risco: ALTO - Potencial de perda financeira por meio de golpe de criptomoedas
The campaign lures victims with fake crypto rewards, likely tricking them into connecting wallets (e.g., MetaMask, Phantom) to drain funds via malicious smart contract interactions or token approvals.
While no forms were detected, the presence of a Credential Harvester kit suggests potential hidden fields or dynamic form injection to capture login credentials or OTPs.
Contains obfuscated JavaScript with 38 detected obfuscation techniques, likely for evasion and malicious payload delivery.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE │
│ - Fake Ryanair crypto promotion email/link │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM LANDS ON FAKE RYANAIR PAGE │
│ - Mimics legitimate Ryanair site │
│ - Displays crypto investment scam │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. VICTIM ENTERS CRYPTO WALLET DETAILS │
│ - Fake form requests wallet credentials │
│ - May include "investment" amount fields │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Form submits via HTTP POST │
│ - Wallet details sent to attacker server │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE │
│ - Fake Ryanair crypto promotion email/link │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM LANDS ON FAKE RYANAIR PAGE │
│ - Mimics legitimate Ryanair site │
│ - Displays crypto investment scam │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. VICTIM ENTERS CRYPTO WALLET DETAILS │
│ - Fake form requests wallet credentials │
│ - May include "investment" amount fields │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Form submits via HTTP POST │
│ - Wallet details sent to attacker server │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)