Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E3A1ED349054AD3790E3D2E89BB9674B7AC2C141CA5B1B0A63FDC76C2BDBCC6DD92110 |
|
CONTENT
ssdeep
|
96:rUuAEYY6ynftSFQG5HclCa2ApMJNFNY4QUbcsySy3M:pXdfcViaJN3Y4QUebc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e1fb0a1a429b5b9 |
|
VISUAL
aHash
|
03181818ffffffff |
|
VISUAL
dHash
|
df696961e016b62c |
|
VISUAL
wHash
|
000008007fffffff |
|
VISUAL
colorHash
|
07240018000 |
|
VISUAL
cropResistant
|
df696961e016b62c,c9e464b430b0b2ec,9d9c9c0d1a9dbd5d,4b0948480b494848 |
• Amenaza: Phishing
• Objetivo: Clientes de DHL
• Método: Impersonación a través de un formulario falso de DHL
• Exfil: ./siftA/Abilli.php
• Indicadores: Discordancia de dominio, solicitud de PII, urgencia.
• Riesgo: Alto
The attacker creates a fraudulent website designed to mimic the DHL website and its services to deceive the user into submitting sensitive information.
The attacker uses a form requesting the user to provide personal and financial information. The information is then sent to a malicious server.
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain