Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T159A2B337A7406B3D4B62039DBA67278EB367518DE6CE09D0E2FDC23E1291D91C536C92 |
|
CONTENT
ssdeep
|
384:6SiYnE93lKOAiEGbGb2T/35UKgx6mf6JYs2KWlhSD9jAmfCG:6SiYEhv/viKgqKwA8t |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0da42cacacece9a |
|
VISUAL
aHash
|
fdc7c7c7c7c3c7c7 |
|
VISUAL
dHash
|
491c1e0e1e0e0e0e |
|
VISUAL
wHash
|
a1c7c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07000000007 |
|
VISUAL
cropResistant
|
491c1e0e1e0e0e0e |
โข Threat: Phishing page impersonating Ledger
โข Target: Ledger cryptocurrency wallet users
โข Method: Fake Ledger Live download page
โข Exfil: Potential data collection via subscription form
โข Indicators: Domain mismatch, free hosting, obfuscated JavaScript
โข Risk: HIGH - Potential for malware distribution or credential theft
The phishing kit impersonates Ledger's official portal to trick users into entering their wallet recovery phrases or private keys. The Credential Harvester component captures input in real-time and transmits it to an attacker-controlled server.
The OTP Stealer and Card Stealer components are designed to intercept one-time passwords and credit card details, likely targeting users who may link payment methods to their crypto wallets for purchases or withdrawals.
Contains obfuscated code with potential credential harvesting or data exfiltration functionality.
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. INITIAL ACCESS โ
โ - Victim directed to fake crypto wallet site โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. FAKE AUTHENTICATION โ
โ - Spoofed login interface presented โ
โ - User prompted for wallet credentials โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL CAPTURE โ
โ - User input collected via web form โ
โ - Data temporarily stored client-side โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA TRANSMISSION โ
โ - Stolen credentials sent via HTTP POST โ
โ - Standard form submission to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. INITIAL ACCESS โ
โ - Victim directed to fake crypto wallet site โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. FAKE AUTHENTICATION โ
โ - Spoofed login interface presented โ
โ - User prompted for wallet credentials โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL CAPTURE โ
โ - User input collected via web form โ
โ - Data temporarily stored client-side โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA TRANSMISSION โ
โ - Stolen credentials sent via HTTP POST โ
โ - Standard form submission to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain