Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16A52B733C5C8263B0B9213C14B82E75BF3DA4081EE23CA99E4FF874D59C9D98E927655 |
|
CONTENT
ssdeep
|
192:PX44Cb7PUhao1RxhlqdcEu88rw4cUcP5d4743MgDUbXlnMbTe4:P44CPmW2ZN1D74rDUzlMbd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c9d33b7249d3531 |
|
VISUAL
aHash
|
3e3c181818183c3c |
|
VISUAL
dHash
|
e271b2b03032f0c8 |
|
VISUAL
wHash
|
3e3c183c3c1c7c7c |
|
VISUAL
colorHash
|
300000101c0 |
|
VISUAL
cropResistant
|
4376e38e9796cce0,31d1a3754d23aad4,e271b2b03032f0c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.