Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T182427232B0E03A3B0193D3D66BB4679BB3E28246DA67160223F5D31D4FDBE49DD42625 |
|
CONTENT
ssdeep
|
192:c03Q/o2dfIOzQY92FtGZPul+iw28wmpa5OYo:cIZ21l8FteuC2bOf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96bcc9cbe198e292 |
|
VISUAL
aHash
|
ff04141634343c7c |
|
VISUAL
dHash
|
383cbcb4ccc9f0c8 |
|
VISUAL
wHash
|
ff0614163c343c7e |
|
VISUAL
colorHash
|
19600030000 |
|
VISUAL
cropResistant
|
006220272738007c,e6d1e17098c84ccc,803a20eca98a9b34,72f47434b43636b6,c0d480a2aa80d003,f87cb4b4c8c9f8cc |
• Amenaza: Phishing/Captura de credenciales
• Objetivo: Clientes de Global Apex Logistics
• Método: Suplantación mediante dominio nuevo
• Exfil: Recolección ofuscada basada en JavaScript
• Indicadores: Dominio muy reciente, imágenes de archivo
• Riesgo: Alto
The site lures users with a professional logistics facade to harvest email and password data.
Uses obfuscated JS to send form input data to a remote collection server.