Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D851952EF00D3644938183DB79D0EAFDFB8B403851952B4A29EED20DB6D47E38CB5646 |
|
CONTENT
ssdeep
|
48:ToRiuVZfXtkoYNCrSQ5ZfEV1j5Ku5auGQA1Kh8VvSslkFNn:Tosgft7YUmQ3s9Kqau9A1Kfn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bf1d41431e1e3a72 |
|
VISUAL
aHash
|
00fb9f9fffffffff |
|
VISUAL
dHash
|
69433333632bcbc7 |
|
VISUAL
wHash
|
00bb83839383eff3 |
|
VISUAL
colorHash
|
07008000c00 |
|
VISUAL
cropResistant
|
433333636b2bcbc7,00201669691a0000 |
• Ameaça: Phishing
• Alvo: Usuários Trezor
• Método: Imitação via hospedagem gratuita.
• Exfil: Provavelmente detalhes da carteira
• Indicadores: Hospedagem gratuita, marca Trezor.
• Risco: Alto
The site likely attempts to steal login credentials, potentially by redirecting the user to a fake login page or by using a keylogger, if the code is injected.
The site could potentially inject malicious JavaScript to steal further information and compromise the user's wallet.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain