Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13821313451991C2EA0C3A2F8F7C0AA1B3C5C8454DF0635027AFC93ED16E7F428E206DA |
|
CONTENT
ssdeep
|
24:hR/CLl8G+/sPQXCwnRwN9ZOlced7RH2h0R08o4E2F:TFGS4ulRwHcl57RWCR08o4Ey |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e66dcd48c9b23296 |
|
VISUAL
aHash
|
ffe3e7e7e7e7e7ff |
|
VISUAL
dHash
|
e246cccc4ccccce0 |
|
VISUAL
wHash
|
7e2066662266677e |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
e246cccc4ccccce0,317171338992f049 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.