Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11D63A66001735A6B02A383D1F6769F9DE0C08350D37B8B69B3FC866F6ECED44AD55262 |
|
CONTENT
ssdeep
|
768:Z34g4iEBSLO++vq2WOE04L35COKhEYp5HV6veb4CIIII7:2gEBSLO++vq2WOELippV6Wb4CIIII7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bbd74d28119594d5 |
|
VISUAL
aHash
|
02a4fe4cc5818100 |
|
VISUAL
dHash
|
964d4c9919252712 |
|
VISUAL
wHash
|
02f5fecfcdc78100 |
|
VISUAL
colorHash
|
300000084c0 |
|
VISUAL
cropResistant
|
964d4c9919252712 |
• Threat: Credential harvesting phishing kit
• Target: Ledger users internationally
• Method: Fake website mimicking Ledger's official site to steal crypto assets
• Exfil: Potential data exfiltration via obfuscated JavaScript
• Indicators: Recent domain, mismatched branding, forms for data input
• Risk: HIGH - Immediate credential and asset theft
Pages with identical visual appearance (based on perceptual hash)