Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T184C17573D014D85D0EB7969DFBC1E29C929AC25AFA7059C7E1D4107F39C0EF180A6369 |
|
CONTENT
ssdeep
|
96:DirN8+s0VN850KN8SChaR1sYYfMmORR1E8VCon0GVCW8wql:DN+a8MdYfMmUU8VCoy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f0de5ece4e0643c |
|
VISUAL
aHash
|
f30f0f3f1f3fffff |
|
VISUAL
dHash
|
e67afec6666e4e4a |
|
VISUAL
wHash
|
130f0f1f03073f2f |
|
VISUAL
colorHash
|
07000000c00 |
|
VISUAL
cropResistant
|
e67afec6666e4e4a |
β’ Threat: Informational page related to setting up Trezor devices.
β’ Target: New Trezor users.
β’ Method: Guides on downloading and using the Trezor Suite app.
β’ Exfil: No data exfiltration.
β’ Indicators: Official brand logo, informational content, and links to download the Trezor Suite app.
β’ Risk: LOW - Informational page with no apparent security risks.
The phishing site impersonates Trezor to trick users into entering their wallet recovery phrases or private keys. These credentials are likely intercepted in real-time via JavaScript event listeners or hidden form submissions.
The OTP Stealer kit suggests the site may capture one-time passwords or 2FA codes, enabling attackers to bypass additional authentication layers for wallet access.
Highly obfuscated JavaScript file with no extracted functions or strings.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 1. VICTIM TARGETED WITH PHISHING LURE β
β - Fake Trezor email/website directs to malicious page β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 2. FAKE WALLET LOGIN PAGE DISPLAYED β
β - Spoofed Trezor interface requests credentials β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 3. CREDENTIALS ENTERED BY VICTIM β
β - User submits wallet recovery phrase/private key β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 4. DATA EXFILTRATED VIA HTTP POST β
β - Form submission sends credentials to attacker serverβ
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 5. ATTACKER GAINS WALLET ACCESS β
β - Harvested credentials used to drain crypto assets β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 1. VICTIM TARGETED WITH PHISHING LURE β
β - Fake Trezor email/website directs to malicious page β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 2. FAKE WALLET LOGIN PAGE DISPLAYED β
β - Spoofed Trezor interface requests credentials β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 3. CREDENTIALS ENTERED BY VICTIM β
β - User submits wallet recovery phrase/private key β
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 4. DATA EXFILTRATED VIA HTTP POST β
β - Form submission sends credentials to attacker serverβ
ββββββββββββββββββββββ¬ββββββββββββββββββββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 5. ATTACKER GAINS WALLET ACCESS β
β - Harvested credentials used to drain crypto assets β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain