Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C1522B79F62512758A8343DAFF3622EEF61340EAD6126BCCD764431CB299AEE8514CC1 |
|
CONTENT
ssdeep
|
192:kojoBNJ5U948cVmwJK2tixv5GQUlcMu9cuGRmKbMpBXp7sfgg8gk:kko+v25K2Yxv1UlrsmMpBZ7eg/B |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f72a552a55aa55a8 |
|
VISUAL
aHash
|
8183e7e7e7e7e7e6 |
|
VISUAL
dHash
|
2b0b8e0c0e0f4d4e |
|
VISUAL
wHash
|
8100c3e7e7c1e7e6 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
2b0b8e0c0e0f4d4e |
โข Threat: Impersonation of Ledger to steal sensitive data.
โข Target: Ledger users.
โข Method: Malicious website to trick users.
โข Exfil: Potentially through Javascript obfuscation.
โข Indicators: Domain mismatch, use of Zapier, 'live' in the domain and Javascript obfuscation.
โข Risk: HIGH
The attacker creates a page that looks like the real Ledger website to trick users into providing their sensitive information. The use of a look-alike domain and branding allows it to appear legitimate.
The malicious javascript code might be used to steal data (e.g. keylogging or data exfiltration)
User fills <input name=username> โ submitForm() โ fetch('https://live-ledge.zapier.app/start') โ credentials sent
User fills <input name=username> โ submitForm() โ fetch('https://live-ledge.zapier.app/start') โ credentials sent
3205eab5-9a11eb2ff901f603.jssubmitFormsendDataPages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain