Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14EB1A71BA244122D03DA037D7AB762ECA72640D1E2142D5E653D052F87F67C9D23FEEA |
|
CONTENT
ssdeep
|
96:n8XKvSzECGA81KPn/lHTqou8WzxnVfL4/aZIRkNEH0IvAoC42:G85CGj2n/lHTHWrEgIv/vAd42 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bf60611d9ccdd0c6 |
|
VISUAL
aHash
|
010167bf9f9fbfbf |
|
VISUAL
dHash
|
330fcc3377736369 |
|
VISUAL
wHash
|
010107bf879fbf85 |
|
VISUAL
colorHash
|
07000000380 |
|
VISUAL
cropResistant
|
330fcc3377736369 |
• Threat: Brand impersonation targeting Ledger users
• Target: Cryptocurrency users
• Method: Dissemination of a fake Ledger website
• Exfil: Likely credential harvesting or private key theft through malicious application downloads
• Indicators: The domain does not match the official Ledger website, the website displays download buttons, the domain name incorporates an unrelated third-party name
• Risk: HIGH - Potential compromise of cryptocurrency funds