Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E120FA040A8BB37438762D576E66F1733D2C241DA86171056F883FE5FEBC15DA1A2A3 |
|
CONTENT
ssdeep
|
96:T0MpOCr6DAY3dGDEkYG7/8IIPGgCPHRosGG0CdZ4g5B9klWCXyCtEtUs8R9h3Jyl:LYCrGAYtG7JR8i5BOwCXyCgrqhFq75N |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c739c6351649788f |
|
VISUAL
aHash
|
c2fb785800003c3c |
|
VISUAL
dHash
|
9656b292ba82e8e8 |
|
VISUAL
wHash
|
c2ffff5800007c7c |
|
VISUAL
colorHash
|
30c00008001 |
|
VISUAL
cropResistant
|
c21a968e8f8e0c9c,9656b292ba82e8e8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.