Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12F531A9D7850601A8B2740F384BB1EC9B73D2C1FE81D55E194B4CBA5B2AC4F5316BB8B |
|
CONTENT
ssdeep
|
768:6yWuWP/suybCqjwqU+d9uX8U895hyDt26147pwTQ5khgGMb0c9xJoRdh7IJKjIOW:GHpVFyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9fd2d0c233f00f8d |
|
VISUAL
aHash
|
fcfe1f073f3fff0f |
|
VISUAL
dHash
|
cc607b1c78709070 |
|
VISUAL
wHash
|
7cfe1f070f1f2100 |
|
VISUAL
colorHash
|
07000000e00 |
|
VISUAL
cropResistant
|
cc607b1c78709070,45452398c4e41145 |
• Threat: Phishing site impersonating Trezor
• Target: Trezor users worldwide
• Method: Fake download page for Trezor Suite app
• Exfil: Potential data exfiltration via obfuscated JavaScript
• Indicators: Free hosting, obfuscated JS, mismatched URL
• Risk: HIGH - Potential for malware distribution
Pages with identical visual appearance (based on perceptual hash)