Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EC3110620122C8965D62D1C412BA976F55D8C15DF6030E46BECCD3ED8BDEE94EDB8601 |
|
CONTENT
ssdeep
|
24:n/CHrnLZxrtv4hSlJ4hL8SYE/hSEaz2Y7hpRrzmC:n2HZdtvCSYhL8SYE/wEalh/zmC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dbe4669899338666 |
|
VISUAL
aHash
|
e0f8bcbcbc3c0000 |
|
VISUAL
dHash
|
0020683070680c00 |
|
VISUAL
wHash
|
f0f8fcfcfcbc0000 |
|
VISUAL
colorHash
|
01000038000 |
|
VISUAL
cropResistant
|
0020683070680c00 |
• Threat: Phishing
• Target: DHL customers
• Method: Impersonation and payment request
• Exfil: Payment information
• Indicators: Urgent message, incorrect domain
• Risk: High
The attacker creates a fake website designed to look like the DHL website to lure victims into entering their information.
The attacker uses a sense of urgency ('must confirm payment') to trick the victim into giving up sensitive data.
Pages with identical visual appearance (based on perceptual hash)
Found 6 other scans for this domain