Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BBA2A337A7406B3D4B62039DBA67279EB367518DE68E09D0E2FDC23E1291D90C536CD2 |
|
CONTENT
ssdeep
|
384:fBiNnE93lKOAiEGbGb2T/35UKgx6mf6JYs2KWlhSD9jAmfCG:fBiNEhv/viKgqKwA8t |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0da42cacacece9a |
|
VISUAL
aHash
|
fdc7c7c7c7c3c7c7 |
|
VISUAL
dHash
|
491c1e0e1e0e0e0e |
|
VISUAL
wHash
|
a1c7c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07000000007 |
|
VISUAL
cropResistant
|
491c1e0e1e0e0e0e |
• Amenaza: Página de phishing que suplanta a Ledger
• Objetivo: Usuarios de Ledger en todo el mundo
• Método: Página falsa de descarga de Ledger Live
• Exfil: No se detectó formulario, pero potencial para descargas maliciosas
• Indicadores: Dominio no relacionado, botón 'Subscribe' sospechoso
• Riesgo: ALTO - Potencial de distribución de malware
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain