Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C481ADF350419C372243C1D45735B71E72C3E6AADE83A6CA53F0A7AA9EC6EE1DD01099 |
|
CONTENT
ssdeep
|
96:nmu5mujj+PaZj4VojI1F/0bL+b4oF+aol:bhAu4qE3OL+se6l |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
daad2fd2a842ea0d |
|
VISUAL
aHash
|
1d7f7bfffffc0400 |
|
VISUAL
dHash
|
71edd1b1b199c827 |
|
VISUAL
wHash
|
11357ffcfd7c0400 |
|
VISUAL
colorHash
|
18241240000 |
|
VISUAL
cropResistant
|
71edd1b1b199c827 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.