Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T116732A4D5451602E873B40F388B71FC8B7385C1FF91902E295B887A6B39D9F5326AB4B |
|
CONTENT
ssdeep
|
768:AyWujwqPyW/18n+sutgX8Uv4ILshJk8347XXalAteIy+ZPYOe5Uxussh6qGqn2gn:iyqyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b32264c9cdcccdac |
|
VISUAL
aHash
|
e7c7c7c7c7efc7c7 |
|
VISUAL
dHash
|
0c0d0d1c1c1c1e1e |
|
VISUAL
wHash
|
c3c3c3c3c3c7c3c2 |
|
VISUAL
colorHash
|
07000000000 |
|
VISUAL
cropResistant
|
0c0d0d1c1c1c1e1e |
β’ Threat: Impersonation
β’ Target: Ledger users
β’ Method: Mimicking Ledger content on a different domain.
β’ Exfil: Unclear. This is likely the first stage, with intent to later phish.
β’ Indicators: Domain, hosting, content style.
β’ Risk: Moderate.
The site mimics Ledger content to create a false sense of security, which is a common approach to get users to enter credentials or visit malicious links.
Exploiting user trust by mimicking the brandβs style and content, which is used to redirect to phishing login pages or malicious websites.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain