Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B7E1403AE18F3720027340E6E79B0FBEB65780A5D151190A597F821C9FE0DDA64BB3D2 |
|
CONTENT
ssdeep
|
96:nvPsptQxv07czo1rQGty/3tij66HCTtWwORtjPxxx9wz2QRJBQZkHcC0UQoRJwFz:bqzM/kik773o/LQFiJ1zc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b86f4e4b464be4b0 |
|
VISUAL
aHash
|
0000ffffffffffff |
|
VISUAL
dHash
|
693914393d343934 |
|
VISUAL
wHash
|
0000c3cfc7cfdfc3 |
|
VISUAL
colorHash
|
0e0000100c0 |
|
VISUAL
cropResistant
|
693914393d343934,01036c6c0771310d |
• Amenaza: Phishing
• Objetivo: Usuarios de Trezor
• Método: Suplantación de dominio y manipulación de contenido
• Exfil: No está claro, pero probablemente apunta a la vulneración de cuentas o la instalación de malware
• Indicadores: Dominio no coincidente, intentos de dirigir a los usuarios al sitio real y destacar el enlace oficial de Trezor Suite.
• Riesgo: Alto
The attackers are using a domain name that is different from the legitimate Trezor website (trezor.io) to lure users into a fake site.
The content is crafted to sound informative but ultimately misleads the user to click on malicious links or download compromised software.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain