Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14A817417A25172180A5A172DB667D3EDEB2940C8F5290B89B5F9C02E30D19C6CC7DFDE |
|
CONTENT
ssdeep
|
96:nkX0qegfXsuaoMcsyABMT6dIFhp6xav7+pVn5kn:exeg/QPyABdEp6xavCpVn5kn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b80ccf63e3c7cc18 |
|
VISUAL
aHash
|
e78f9fcfc7cfcfcf |
|
VISUAL
dHash
|
4cbcb49c9c9c9c98 |
|
VISUAL
wHash
|
c7c35e4e46464e4e |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
4cbcb49c9c9c9c98 |
• Threat: Phishing
• Target: Ledger users
• Method: Impersonation via free hosting
• Exfil: Unknown, likely to steal credentials or download malware
• Indicators: Free hosting, brand logo, content match
• Risk: High
The site likely attempts to harvest Ledger user's seed phrases or to download a malicious software.
Pages with identical visual appearance (based on perceptual hash)