Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B7E1403AE18F3720027340E6E79B0FBEB65780A5D151190A597F821C9FE0DDA64BB3D2 |
|
CONTENT
ssdeep
|
96:nvPsptQxv07czo1rQGty/3tij66HCTtWwORtjPxxx9wz2QRJBQZkHcC0UQoRJwFz:bqzM/kik773o/LQFiJ1zc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b86f4e4b464be4b0 |
|
VISUAL
aHash
|
0000ffffffffffff |
|
VISUAL
dHash
|
693914393d343934 |
|
VISUAL
wHash
|
0000c3cfc7cfdfc3 |
|
VISUAL
colorHash
|
0e0000100c0 |
|
VISUAL
cropResistant
|
693914393d343934,01036c6c0771310d |
⢠Threat: Phishing
⢠Target: Trezor users
⢠Method: Domain spoofing & content manipulation
⢠Exfil: Unclear, but likely aiming for account compromise or malware installation
⢠Indicators: Mismatched domain, attempts to direct users to the real site, and highlight the official Trezor Suite link.
⢠Risk: High
The attackers are using a domain name that is different from the legitimate Trezor website (trezor.io) to lure users into a fake site.
The content is crafted to sound informative but ultimately misleads the user to click on malicious links or download compromised software.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain