Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19B22953023441E3E5A2BC698F6A4B31E619BE388D62F915CE2AF027557C7D82DC375D8 |
|
CONTENT
ssdeep
|
192:HSB6lsI1nqPDSMsP2F+7eezgXRwXCCY/1Y2hCYOSsNu:HSUls5L+gXRwXCCYtYXYr |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b4d34326d98c667 |
|
VISUAL
aHash
|
000c3c3c203c1c00 |
|
VISUAL
dHash
|
0448405042793902 |
|
VISUAL
wHash
|
103c3c3c3c3c3c30 |
|
VISUAL
colorHash
|
38006000018 |
|
VISUAL
cropResistant
|
0448405042793902 |
• Threat: DHL phishing targeting account access.
• Target: DHL users.
• Method: Fake license and access path request.
• Exfil: Likely credentials and potentially other data to unknown endpoint.
• Indicators: Non official website URL, recent domain, obfuscation detected and javascript form submission detected.
• Risk: HIGH - Credentials theft.
The phishing kit captures user credentials through fake form fields ('Votre licence', 'Chemin d accès'). Data is likely exfiltrated via HTTP POST requests to a command-and-control server.
The kit includes functionality to intercept one-time passwords (OTPs), enabling attackers to bypass multi-factor authentication on compromised accounts.
Obfuscated JavaScript files containing credential harvesting and OTP interception logic.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain