Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B7E1403AE18F3720027340E6E79B0FBEB65780A5D151190A597F821C9FE0DDA64BB3D2 |
|
CONTENT
ssdeep
|
96:nvPsptQxv07czo1rQGty/3tij66HCTtWwORtjPxxx9wz2QRJBQZkHcC0UQoRJwFz:bqzM/kik773o/LQFiJ1zc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b86f4e4b464be4b0 |
|
VISUAL
aHash
|
0000ffffffffffff |
|
VISUAL
dHash
|
693914393d343934 |
|
VISUAL
wHash
|
0000c3cfc7cfdfc3 |
|
VISUAL
colorHash
|
0e0000100c0 |
|
VISUAL
cropResistant
|
693914393d343934,01036c6c0771310d |
• Ameaça: Phishing
• Alvo: Usuários Trezor
• Método: Falsificação de domínio e manipulação de conteúdo
• Exfil: Não está claro, mas provavelmente visa a invasão de contas ou a instalação de malware
• Indicadores: Domínio incompatível, tentativas de direcionar os usuários ao site real e destacar o link oficial do Trezor Suite.
• Risco: Alto
The attackers are using a domain name that is different from the legitimate Trezor website (trezor.io) to lure users into a fake site.
The content is crafted to sound informative but ultimately misleads the user to click on malicious links or download compromised software.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain