Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A8632B9A2844701A476740E394BB2AC9F7391C2FB91C05E1A4B4CBE572B88F5716BF4F |
|
CONTENT
ssdeep
|
768:OyWuPysulWz//WMX911cCZ/ubUqBHdLrY5Lv8n+DHnxRSjwqMo1X8U6sX1/BDF4z:YnRmbxXiyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91eeee99e152106d |
|
VISUAL
aHash
|
ffff004e0a0e0000 |
|
VISUAL
dHash
|
031a1c989a9c1ccb |
|
VISUAL
wHash
|
ffff0e6e0e0f0020 |
|
VISUAL
colorHash
|
324010000c0 |
|
VISUAL
cropResistant
|
030041d696c20203,fca4a4b0b6eacec3,0000000000020408,60c4848480828280,030303c3d3030303,1afc989a98dc00cb |
• Ameaça: Phishing
• Alvo: Usuários Ledger
• Método: Falsificação de domínio e imitação visual
• Exfil: Potencialmente credenciais ou acesso à carteira se houvesse formulários. Provavelmente, o Javascript será usado para roubar dados assim que uma carteira for conectada.
• Indicadores: Domínio suspeito, marca Ledger, mas hospedado em uma plataforma de reputação questionável.
• Risco: Alto
The site will likely contain Javascript to harvest Ledger user credentials or trick the user into connecting their wallet.
Once the user interacts with the page, the injected code will steal assets from the user's connected Ledger wallet.
polyfills-c67a75d1b6f99dc8.jsPages with identical visual appearance (based on perceptual hash)