Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T107E3957A90F7173F893E7392BAA12721A997471B828517E38AFC67851F94ECE3D03144 |
|
CONTENT
ssdeep
|
768:nha/yEl4dJImYf+UgNYoqsZr6AuchqZ5cBX0Y:nh6ssxULqs16AuchqWXT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9010edef453cba4b |
|
VISUAL
aHash
|
ff0d040400ffffff |
|
VISUAL
dHash
|
22999dbcc8218800 |
|
VISUAL
wHash
|
c30c040400ffffff |
|
VISUAL
colorHash
|
07041010000 |
|
VISUAL
cropResistant
|
3a22d9999dbd9ccc,c8e2313844000000,d9999d9dbc9cccea |
• Ameaça: Ataque de phishing para roubo de credenciais
• Alvo: Clientes da DHL
• Método: Página de login falsa da DHL para roubar e-mail e senha
• Exfil: Dados enviados para /landingpages/99897ef0-5700-48f4-9c83-b686955ea6bc/lqor80p1_fgstvteir6p5uagd04pjczadrdfkhs_dlq
• Indicadores: Domínio não corresponde, envio de formulário com JavaScript, design genérico
• Risco: ALTO - Possível roubo imediato de credenciais
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain