Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1250496B6A1F6133F483EB396F1E2371566A7871B83421BE35AFC16941F88B8E2D07544 |
|
CONTENT
ssdeep
|
3072:rqsHE3TRFWeXVUF3MQ4orPqfmDeLWpy++Kl8zKvAWWjs6cAQzAZOHZqyRMXn6PX5:esHE3TRFWeXVUF3MQ4orPqfmDeLWpy+T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9010edef453cba4b |
|
VISUAL
aHash
|
ff0d040400ffffff |
|
VISUAL
dHash
|
22999dbcc8218800 |
|
VISUAL
wHash
|
c30c040400ffffff |
|
VISUAL
colorHash
|
07041010000 |
|
VISUAL
cropResistant
|
3a22d9999dbd9ccc,c8e2313844000000,d9999d9dbc9cccea |
• Amenaza: Phishing
• Objetivo: Clientes de DHL
• Método: Suplantación de identidad a través de una página de inicio de sesión falsa.
• Exfil: /pages/4919fca7-004d-458a-b3a2-0233482154e3/84bc49718c66a64a8a561e35d453ef484b53e95980a06fae81ce648caa314def627f5f63f77904d53231d4249b1c7e71544e55b1d39a69b7254a2a48f5fd3d34
• Indicadores: Dominio no relacionado, formulario de inicio de sesión.
• Riesgo: ALTO
The attacker is attempting to steal user credentials (email and password) by presenting a fake login form that mimics the appearance of the legitimate DHL website.
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain