Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T114C16333D510E81A1FB6958CFAC0E19C9267D20BF63098C7B2C5615F6AC1EF598A137D |
|
CONTENT
ssdeep
|
96:uyC3aR1sYlYfMmORR1E8VConyro+ByOhl:umdCfMmUU8VCoUn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88dd227da8d5a2d5 |
|
VISUAL
aHash
|
ff187e1818000041 |
|
VISUAL
dHash
|
b271e8b2300e86c5 |
|
VISUAL
wHash
|
ff007e18bcff4041 |
|
VISUAL
colorHash
|
38006000080 |
|
VISUAL
cropResistant
|
b271e8b2300e86c5 |
• Ameaça: Phishing de exchange de criptomoedas
• Alvo: Usuários do Coinbase Pro
• Método: Imitação da plataforma de negociação Coinbase Pro
• Exfil: Desconhecido, provavelmente roubo de credenciais e chaves de API
• Indicadores: Domínio não oficial framer.media, marca d'água "Made in Framer"
• Risco: ALTO - Potencial para apropriação de conta e roubo de fundos
The phishing page mimics Coinbase's login interface to trick users into entering their wallet credentials. The harvested credentials are likely exfiltrated in real-time to an attacker-controlled server for immediate exploitation.
The presence of 'Deposit' and 'Withdraw' buttons suggests the page may simulate transactions to deceive users into believing they are interacting with a legitimate platform, potentially leading to further credential or seed phrase exposure.
Small JavaScript file with high obfuscation, likely used for credential harvesting.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE │
│ - Email/SMS with fake Coinbase link │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE COINBASE SITE │
│ - Cloned Coinbase login page displayed │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT │
│ - Victim enters wallet credentials │
│ - Form appears identical to legitimate Coinbase │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIAL EXFILTRATION │
│ - Data sent via HTTP POST to attacker-controlled │
│ server (standard form submission) │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE │
│ - Email/SMS with fake Coinbase link │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE COINBASE SITE │
│ - Cloned Coinbase login page displayed │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT │
│ - Victim enters wallet credentials │
│ - Form appears identical to legitimate Coinbase │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIAL EXFILTRATION │
│ - Data sent via HTTP POST to attacker-controlled │
│ server (standard form submission) │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain