Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17A6377F34048B63E418697D4AA39F7B9F3A34094CE554A9983F0C30EFAC6F94CD69994 |
|
CONTENT
ssdeep
|
768:s5w4dOBFSG0ZhjPZ0u7ZKlBNNd9hh8xaBIPf:54bSDDHmf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93336c6cac939393 |
|
VISUAL
aHash
|
000c6c4c0c003c7e |
|
VISUAL
dHash
|
b288c8989808f0f0 |
|
VISUAL
wHash
|
004e6e7e4e047e7e |
|
VISUAL
colorHash
|
31200030000 |
|
VISUAL
cropResistant
|
aab2a2aab2bab2c4,b288c8989808f0f0 |
• Threat: Brand impersonation phishing
• Target: Ledger users
• Method: Displays Ledger branding on a fake website to deceive users
• Exfil: Form actions lead to s1909208.t.eloqua.com/e/f2
• Indicators: New domain (6 days old), mismatched domain, Ledger branding
• Risk: HIGH - Potential for credential theft or malware distribution.