Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C472A833A144323E1E5311822BD0275EF766D085E747151CCEB9934E9BD6E0FEE7288A |
|
CONTENT
ssdeep
|
192:cTcFz0zcOXc9xW4Y0uAyp6RyIIQzvUbAVC12S65xvFCkfOAZsZ4KA3IL7d/z1RPb:LUpfIIG1LgXbGj9UFx28mdOXX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ea11ee9512ec936c |
|
VISUAL
aHash
|
0000000000fff3ff |
|
VISUAL
dHash
|
cec3c7c7ffe22325 |
|
VISUAL
wHash
|
0060616103fff3ff |
|
VISUAL
colorHash
|
030000001c0 |
|
VISUAL
cropResistant
|
2a9bdb5312135a5a,9aa535372425a5dd,b1a5858b8b6466d3,6d6dd2961696169f,282c9a9a1a929a9a,f000230323272525,9241c4d0c1c4c0c2,aa82a28ab2a2a2b2,8241c1c2c4c1c0c4,cecfc3c3c7c7eff8,009429d4d4d4d4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.