Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C1630AAE6851601A477740E384BB1BC9B73D1C2FE92C05D194B8C7F5B2A88F5316BB4B |
|
CONTENT
ssdeep
|
1536:K4bf6uxBepLU4MNAeiEJ+4cprPAfCWOkqLPWVEmEE2yOloQzZs8oWQbp:1Wj9ds8oWA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9fd2d0c233f00f8d |
|
VISUAL
aHash
|
fcfe1f073f3fff0f |
|
VISUAL
dHash
|
cc607b1c78709070 |
|
VISUAL
wHash
|
7cfe1f070f1f2100 |
|
VISUAL
colorHash
|
07000000e00 |
|
VISUAL
cropResistant
|
cc607b1c78709070,45452398c4e41145 |
• Threat: Brand impersonation phishing.
• Target: Trezor users.
• Method: The site attempts to trick users into downloading a malicious application by using the Trezor brand on a non-official domain.
• Exfil: Unknown, likely leads to malware download or credential theft on a subsequent page.
• Indicators: Free hosting on typedream.app, domain name mismatch with the official Trezor website (trezor.io).
• Risk: HIGH - Poses a significant risk as it can lead to downloading malicious software.
Pages with identical visual appearance (based on perceptual hash)