Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13A62C673A025BC3756138BE0B8A1B71EF9A3D30CDC1614A169FC93A12FD9D51A48F74A |
|
CONTENT
ssdeep
|
384:9+G+rS1M2C1MEGXoyytTuVWjh+hwYuYVY1:EhrS141KXP4Cd/561 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b13166666430cfcf |
|
VISUAL
aHash
|
c3c3ffcfffffffff |
|
VISUAL
dHash
|
8e9e70900c200000 |
|
VISUAL
wHash
|
c0c0ecccc4c0f070 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
8e9e70900c200000,728c9452d3b69e90 |
• Amenaza: Phishing por suplantación de identidad
• Objetivo: Clientes de Canada Post
• Método: Formulario engañoso, pidiendo reprogramar un paquete.
• Exfil: Potencialmente recolectar información personal si se presenta un formulario.
• Indicadores: Enlace a una dirección IP, alojado en Google Forms, suplantación.
• Riesgo: ALTO
The attacker is impersonating Canada Post to trick users into providing information. This is done through a fake delivery notification.
The 'reschedule' link is designed to redirect users to a malicious website or harvest information.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain