Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T159A2B337A7406B3D4B62039DBA67278EB367518DE6CE09D0E2FDC23E1291D91C536C92 |
|
CONTENT
ssdeep
|
384:6SiYnE93lKOAiEGbGb2T/35UKgx6mf6JYs2KWlhSD9jAmfCG:6SiYEhv/viKgqKwA8t |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0da42cacacece9a |
|
VISUAL
aHash
|
fdc7c7c7c7c3c7c7 |
|
VISUAL
dHash
|
491c1e0e1e0e0e0e |
|
VISUAL
wHash
|
a1c7c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07000000007 |
|
VISUAL
cropResistant
|
491c1e0e1e0e0e0e |
โข Threat: Phishing page impersonating Ledger
โข Target: Ledger users worldwide
โข Method: Fake Ledger Live download page
โข Exfil: No form detected, but obfuscated JS present
โข Indicators: Domain mismatch, free hosting, suspicious content
โข Risk: HIGH - Potential for malware distribution
The phishing kit impersonates Ledger's official portal to trick users into entering their wallet credentials. The Credential Harvester kit likely captures input in real-time and exfiltrates it to an attacker-controlled server.
The OTP Stealer and Card Stealer kits suggest the campaign also targets one-time passwords and payment card details, potentially enabling unauthorized transactions or account takeovers.
Contains potential credential harvesting and data exfiltration logic.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain