Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1613130610126C8965DA2D1C412BA876F15C8C14DF6030E46BFCCD3EC8BDEE90DDB8601 |
|
CONTENT
ssdeep
|
24:n/CHrnLZxrtv4hSlJ4y98SYE/hSEaz2Y7hpgzmC:n2HZdtvCSY28SYE/wEalhyzmC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dbe4669899338666 |
|
VISUAL
aHash
|
e0f8bcbcbc3c0000 |
|
VISUAL
dHash
|
0020683070680c00 |
|
VISUAL
wHash
|
f0f8fcfcfcbc0000 |
|
VISUAL
colorHash
|
01000038000 |
|
VISUAL
cropResistant
|
0020683070680c00 |
• Amenaza: Phishing
• Objetivo: Clientes de DHL
• Método: Impersonando el servicio de seguimiento de DHL para robar información de pago.
• Exfil: Desconocido, probablemente a un servidor controlado por el atacante.
• Indicadores: Dominio no relacionado con DHL, solicitud urgente de verificación de pago.
• Riesgo: ALTO
The attacker aims to steal the user's payment information by having them enter a code.
Pages with identical visual appearance (based on perceptual hash)
Found 6 other scans for this domain