Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EFA1DC349058AC3790E3D2D89BB9674B7AC6C142CA171B0963FDD76C2FDBC86DE92110 |
|
CONTENT
ssdeep
|
96:PUuAEYU6ynftSaQG5HclC362ApMNKFNSFUycsySsM:1XxfcYiMNK3SFUvy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e1fb0a1a429b5b9 |
|
VISUAL
aHash
|
03181818ffffffff |
|
VISUAL
dHash
|
df696961e016b60c |
|
VISUAL
wHash
|
000008007fffffff |
|
VISUAL
colorHash
|
07240018000 |
|
VISUAL
cropResistant
|
df696961e016b60c,c9e464b430b0b2ec,9d9c9c0d1a9dbd5d,4b0948480b494848 |
โข Threat: Phishing
โข Target: DHL customers
โข Method: Impersonation to steal personal and financial information.
โข Exfil: veria.php
โข Indicators: Unrelated domain, request for personal and payment information, urgency tactics.
โข Risk: HIGH
The attackers are employing a credential harvesting attack to collect personal and financial information by posing as DHL and requesting the users to input their data in a form.
The attacker is impersonating DHL to trick the victims. The visual elements resemble DHL's branding.
Pages with identical visual appearance (based on perceptual hash)
Found 6 other scans for this domain