Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14D72543251042A3EC22303D9AFD723D8B3F38589EA9D09E1D2F8D2781753DA5D7265D4 |
|
CONTENT
ssdeep
|
384:ICgCdmeRER0AbyOVqsdYjA8bTPg7n4TbeI+WjtjAG:BgCdmeRE7pVq4mA8bTY74TbeI+05AG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
880af3f3e2c8ccda |
|
VISUAL
aHash
|
ff000000ffffffff |
|
VISUAL
dHash
|
69fff3f38f189e1e |
|
VISUAL
wHash
|
050000003fffffff |
|
VISUAL
colorHash
|
06000280030 |
|
VISUAL
cropResistant
|
01480169499100ff,ae80897971c980ae,22001e36201e3600,fffff3fbb3f3cfff |
• Amenaza: Kit de phishing para robo de credenciales
• Objetivo: Usuarios de Ledger internacionalmente
• Método: Formulario falso de suscripción que roba direcciones de correo electrónico
• Exfil: Datos enviados a servidor desconocido
• Indicadores: Hosting gratuito, discrepancia de dominio, JavaScript ofuscado
• Riesgo: ALTO - Potencial de robo de credenciales
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain