Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1250496B6A1F6133F483EB396F1E2371566A7871B83421BE35AFC16941F88B8E2D07544 |
|
CONTENT
ssdeep
|
3072:rqsHE3TRFWeXVUF3MQ4orPqfmDeLWpy++Kl8zKvAWWjs6cAQzAZOHZqyRMXn6PX5:esHE3TRFWeXVUF3MQ4orPqfmDeLWpy+T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9010edef453cba4b |
|
VISUAL
aHash
|
ff0d040400ffffff |
|
VISUAL
dHash
|
22999dbcc8218800 |
|
VISUAL
wHash
|
c30c040400ffffff |
|
VISUAL
colorHash
|
07041010000 |
|
VISUAL
cropResistant
|
3a22d9999dbd9ccc,c8e2313844000000,d9999d9dbc9cccea |
⢠Threat: Phishing
⢠Target: DHL customers
⢠Method: Impersonation through a fake login page.
⢠Exfil: /pages/4919fca7-004d-458a-b3a2-0233482154e3/84bc49718c66a64a8a561e35d453ef484b53e95980a06fae81ce648caa314def627f5f63f77904d53231d4249b1c7e71544e55b1d39a69b7254a2a48f5fd3d34
⢠Indicators: Unrelated domain, login form
⢠Risk: HIGH
The attacker is attempting to steal user credentials (email and password) by presenting a fake login form that mimics the appearance of the legitimate DHL website.
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain