Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T159A2B337A7406B3D4B62039DBA67278EB367518DE6CE09D0E2FDC23E1291D91C536C92 |
|
CONTENT
ssdeep
|
384:6SiYnE93lKOAiEGbGb2T/35UKgx6mf6JYs2KWlhSD9jAmfCG:6SiYEhv/viKgqKwA8t |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0da42cacacece9a |
|
VISUAL
aHash
|
fdc7c7c7c7c3c7c7 |
|
VISUAL
dHash
|
491c1e0e1e0e0e0e |
|
VISUAL
wHash
|
a1c7c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07000000007 |
|
VISUAL
cropResistant
|
491c1e0e1e0e0e0e |
• Ameaça: Página de phishing que imita a Ledger
• Alvo: Usuários da Ledger em todo o mundo
• Método: Página falsa de download do Ledger Live
• Exfil: Nenhum formulário detectado, mas JS ofuscado presente
• Indicadores: Domínio não coincidente, hospedagem gratuita, conteúdo suspeito
• Risco: ALTO - Possível distribuição de malware
The phishing kit impersonates Ledger's official portal to trick users into entering their wallet credentials. The Credential Harvester kit likely captures input in real-time and exfiltrates it to an attacker-controlled server.
The OTP Stealer and Card Stealer kits suggest the campaign also targets one-time passwords and payment card details, potentially enabling unauthorized transactions or account takeovers.
Contains potential credential harvesting and data exfiltration logic.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain