Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A8632B9A2844701A476740E394BB2AC9F7391C2FB91C05E1A4B4CBE572B88F5716BF4F |
|
CONTENT
ssdeep
|
768:OyWuPysulWz//WMX911cCZ/ubUqBHdLrY5Lv8n+DHnxRSjwqMo1X8U6sX1/BDF4z:YnRmbxXiyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91eeee99e152106d |
|
VISUAL
aHash
|
ffff004e0a0e0000 |
|
VISUAL
dHash
|
031a1c989a9c1ccb |
|
VISUAL
wHash
|
ffff0e6e0e0f0020 |
|
VISUAL
colorHash
|
324010000c0 |
|
VISUAL
cropResistant
|
030041d696c20203,fca4a4b0b6eacec3,0000000000020408,60c4848480828280,030303c3d3030303,1afc989a98dc00cb |
• Amenaza: Phishing
• Objetivo: Usuarios de Ledger
• Método: Suplantación de dominio e imitación visual
• Exfil: Potencialmente credenciales o acceso a la billetera si hubiera formularios. Probablemente se usará Javascript para robar datos una vez que se conecte una billetera.
• Indicadores: Dominio sospechoso, marca Ledger, pero alojado en una plataforma de reputación dudosa.
• Riesgo: Alto
The site will likely contain Javascript to harvest Ledger user credentials or trick the user into connecting their wallet.
Once the user interacts with the page, the injected code will steal assets from the user's connected Ledger wallet.
polyfills-c67a75d1b6f99dc8.jsPages with identical visual appearance (based on perceptual hash)