Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C1522B79F62512758A8343DAFF3622EEF61340EAD6126BCCD764431CB299AEE8514CC1 |
|
CONTENT
ssdeep
|
192:kojoBNJ5U948cVmwJK2tixv5GQUlcMu9cuGRmKbMpBXp7sfgg8gk:kko+v25K2Yxv1UlrsmMpBZ7eg/B |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f72a552a55aa55a8 |
|
VISUAL
aHash
|
8183e7e7e7e7e7e6 |
|
VISUAL
dHash
|
2b0b8e0c0e0f4d4e |
|
VISUAL
wHash
|
8100c3e7e7c1e7e6 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
2b0b8e0c0e0f4d4e |
โข Threat: Impersonation phishing
โข Target: Ledger users
โข Method: Hosted on Zapier, impersonating the brand.
โข Exfil: Not applicable in this static page example
โข Indicators: Mismatched domain, brand impersonation
โข Risk: HIGH
The attacker creates a page that closely resembles Ledger's legitimate content, aiming to trick users into believing it's a genuine site.
The content uses the legitimate information to gain users' trust and ultimately steal credentials or install malicious software.
User fills <input name='username'> โ sendData() โ fetch('https://interfaces.zapier.com/_next/static/chunks/3205eab5-9a11eb2ff901f603.js') โ credentials sent
User fills <input name='username'> โ sendData() โ fetch('https://interfaces.zapier.com/_next/static/chunks/3205eab5-9a11eb2ff901f603.js') โ credentials sent
3205eab5-9a11eb2ff901f603.jssendDatasubmitFormPages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain