Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B2C13FF72056E63701A392D223785F1B7AD2879EC98716005AECD39E5FD6E0CFD42281 |
|
CONTENT
ssdeep
|
96:TwWDF7cE7L2ln16ZUmvs+I/V+oilDsBBm:vDGmin1HOogDCBm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc338d338d31cd33 |
|
VISUAL
aHash
|
0300000000181838 |
|
VISUAL
dHash
|
820102200c3032b2 |
|
VISUAL
wHash
|
c3000000003c3c3c |
|
VISUAL
colorHash
|
38000038000 |
|
VISUAL
cropResistant
|
024202626a020202,820102200c3032b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters credit/debit card details including CVV and expiration. Card data is captured and can be used for fraudulent transactions or sold on dark web markets.