Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14CA1ED309054AD3790E3D2E89BB9674B7AC2C141CA5B1B0963FDC76C2BDBCC6DD92110 |
|
CONTENT
ssdeep
|
96:rUuAEYY6ynftSFQG5HclCa2ApMJNFNYUQUbcsySy3M:pXdfcViaJN3YUQUebc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e1fb0a1a429b5b9 |
|
VISUAL
aHash
|
03181818ffffffff |
|
VISUAL
dHash
|
df696961e016b62c |
|
VISUAL
wHash
|
000008007fffffff |
|
VISUAL
colorHash
|
07240018000 |
|
VISUAL
cropResistant
|
df696961e016b62c,c9e464b430b0b2ec,9d9c9c0d1a9dbd5d,4b0948480b494848 |
• Threat: Phishing
• Target: DHL customers
• Method: Impersonation and form-based data theft
• Exfil: ./siftA/Abilli.php
• Indicators: Domain mismatch, requests sensitive data, urgency tactics
• Risk: HIGH
The attacker aims to collect user credentials and personal information through a form that mimics a legitimate DHL login page, tricking users into entering their data. The attacker uses obfuscation to hide its malicious code.
The attacker uses social engineering techniques, such as creating a sense of urgency about a 'Shipment On Hold,' to persuade victims to enter their data.
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain