Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T182427232B0E03A3B0193D3D66BB4679BB3E28246DA67160223F5D31D4FDBE49DD42625 |
|
CONTENT
ssdeep
|
192:c03Q/o2dfIOzQY92FtGZPul+iw28wmpa5OYo:cIZ21l8FteuC2bOf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96bcc9cbe198e292 |
|
VISUAL
aHash
|
ff04141634343c7c |
|
VISUAL
dHash
|
383cbcb4ccc9f0c8 |
|
VISUAL
wHash
|
ff0614163c343c7e |
|
VISUAL
colorHash
|
19600030000 |
|
VISUAL
cropResistant
|
006220272738007c,e6d1e17098c84ccc,803a20eca98a9b34,72f47434b43636b6,c0d480a2aa80d003,f87cb4b4c8c9f8cc |
• Threat: Phishing/Credential Harvesting
• Target: Global Apex Logistics customers
• Method: Impersonation via fresh domain
• Exfil: JavaScript-based obfuscated collection
• Indicators: Extremely young domain, stock vault imagery
• Risk: High
The site lures users with a professional logistics facade to harvest email and password data.
Uses obfuscated JS to send form input data to a remote collection server.