Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T108D1DDE561D59477015363DFB1AAA736B1F08948EA896A22F7FC43E873DBC10F842B41 |
|
CONTENT
ssdeep
|
96:kb2UNG9Dj3+G6U6UAyzjNXsd3FL+LU//Z996k0SzIEhS8V48/vEDY:kb2U49u7U5Ay9y3H9k8hGY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a1b29bd96878786 |
|
VISUAL
aHash
|
01003c3cffffffff |
|
VISUAL
dHash
|
9f13cd69603f93c8 |
|
VISUAL
wHash
|
00003c04ffc3ff7f |
|
VISUAL
colorHash
|
06240018000 |
|
VISUAL
cropResistant
|
9f13cd69603f93c8,3333b2909e8adee0,13535b2753636323,0000081010100800 |
• Amenaza: Kit de phishing para robo de credenciales
• Objetivo: Clientes de DHL a nivel internacional
• Método: Página falsa de seguimiento de envíos solicitando pago
• Exfil: Desconocido, probablemente API personalizada
• Indicadores: Dominio no relacionado, hosting gratuito, marca no coincidente
• Riesgo: ALTO - Robo inmediato de credenciales y financiero
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain