Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1613130610126C8965DA2D1C412BA876F15C8C14DF6030E46BFCCD3EC8BDEE90DDB8601 |
|
CONTENT
ssdeep
|
24:n/CHrnLZxrtv4hSlJ4y98SYE/hSEaz2Y7hpgzmC:n2HZdtvCSY28SYE/wEalhyzmC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dbe4669899338666 |
|
VISUAL
aHash
|
e0f8bcbcbc3c0000 |
|
VISUAL
dHash
|
0020683070680c00 |
|
VISUAL
wHash
|
f0f8fcfcfcbc0000 |
|
VISUAL
colorHash
|
01000038000 |
|
VISUAL
cropResistant
|
0020683070680c00 |
• Threat: Phishing
• Target: DHL customers
• Method: Impersonating DHL's tracking service to steal payment information.
• Exfil: Unknown, likely to a server controlled by the attacker.
• Indicators: Domain unrelated to DHL, urgent request for payment verification.
• Risk: HIGH
The attacker aims to steal the user's payment information by having them enter a code.
Pages with identical visual appearance (based on perceptual hash)
Found 6 other scans for this domain