Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12F531A9D7850601A8B2740F384BB1EC9B73D2C1FE81D55E194B4CBA5B2AC4F5316BB8B |
|
CONTENT
ssdeep
|
768:6yWuWP/suybCqjwqU+d9uX8U895hyDt26147pwTQ5khgGMb0c9xJoRdh7IJKjIOW:GHpVFyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9fd2d0c233f00f8d |
|
VISUAL
aHash
|
fcfe1f073f3fff0f |
|
VISUAL
dHash
|
cc607b1c78709070 |
|
VISUAL
wHash
|
7cfe1f070f1f2100 |
|
VISUAL
colorHash
|
07000000e00 |
|
VISUAL
cropResistant
|
cc607b1c78709070,45452398c4e41145 |
• Amenaza: Sitio de phishing que suplanta a Trezor
• Objetivo: Usuarios de Trezor en todo el mundo
• Método: Página de descarga falsa para la aplicación Trezor Suite
• Exfil: Posible exfiltración de datos a través de JavaScript ofuscado
• Indicadores: Hosting gratuito, JS ofuscado, URL no coincidente
• Riesgo: ALTO - Potencial distribución de malware
Pages with identical visual appearance (based on perceptual hash)