Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T178156CA87192F46587B784E5807F110EF23E291A640C8460F375DCD878B899EB277FAD |
|
CONTENT
ssdeep
|
24576:Gaz9WEWYn2B8uaeHV1j8R4AFdZtFBDar6wpf:XR+B8uaeHV1j8R4AFdZtF9O6wpf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9fd2d0c233f00f8d |
|
VISUAL
aHash
|
fcfe1f073f3fff0f |
|
VISUAL
dHash
|
cc607b1c78709070 |
|
VISUAL
wHash
|
7cfe1f070f1f2100 |
|
VISUAL
colorHash
|
07000000e00 |
|
VISUAL
cropResistant
|
cc607b1c78709070,45452398c4e41145 |
• Threat: Malware distribution/information harvesting phishing targeting Trezor users.
• Target: Trezor users intending to download software for their hardware wallet.
• Method: The page presents itself as an official Trezor download site, but the download link likely leads to malware.
• Exfil: Unknown, likely data exfiltration via malicious download or possible data submission if any form fields were present on other pages of the site.
• Indicators: Free hosting on Typedream, domain mismatch, Trezor brand impersonation.
• Risk: HIGH - Potential malware infection or data theft from a compromised download.
Pages with identical visual appearance (based on perceptual hash)