Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B3110610222C8965D62D1C422BA976F15D8C15DF6030E46BECCE3AD8ADED94DDB8601 |
|
CONTENT
ssdeep
|
24:n/CHrnLZxrtv4hSlJ4cXk8SYE/hSEaz2Y7hpdzmC:n2HZdtvCSYcU8SYE/wEalhnzmC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dbe4669899338666 |
|
VISUAL
aHash
|
e0f8bcbcbc3c0000 |
|
VISUAL
dHash
|
0020683070680c00 |
|
VISUAL
wHash
|
f0f8fcfcfcbc0000 |
|
VISUAL
colorHash
|
01000038000 |
|
VISUAL
cropResistant
|
0020683070680c00 |
• Ameaça: Phishing
• Alvo: Clientes DHL
• Método: Imitação e pedido de pagamento
• Exfil: Informações de pagamento
• Indicadores: Solicitação de confirmação de pagamento, urgência, domínio incompatível.
• Risco: Alto
The attacker attempts to steal payment information by mimicking a legitimate DHL tracking page and requesting a confirmation.
Pages with identical visual appearance (based on perceptual hash)
Found 6 other scans for this domain