Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T175E200346040A9778467EACDA768D31FB2C2969CEB138F05A7FA438C47F7C98ED01A15 |
|
CONTENT
ssdeep
|
384:mE9eNKlV2PLsUUEL7w3CKPMMJhiErpSgvqeZTof+5jGSXVeiqf:19eU3ML6ELGCKTDA6q8HGSQPf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc1b33199967cccc |
|
VISUAL
aHash
|
00003c3c3c3c0000 |
|
VISUAL
dHash
|
304c22b2b2b24c0e |
|
VISUAL
wHash
|
00c33f3f3f1b8300 |
|
VISUAL
colorHash
|
0e402000240 |
|
VISUAL
cropResistant
|
8a4e6a6a63730d69,304c22b2b2b24c0e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.