Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T164F100715244327B42A286CAEB60FF7BA3954344D6131A25A2F4C34F8BDAF44CE9374B |
|
CONTENT
ssdeep
|
96:TpYb2siSJSJSeBsjAbBowcg0Ema59JC3iObGPTu4VH7oJLapZnlzr0pwiRggq:NYb2sf44eBAmowc+5SJlLktEq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f3be4cba490c6632 |
|
VISUAL
aHash
|
00ffffffffff0000 |
|
VISUAL
dHash
|
71080c080e08aaaa |
|
VISUAL
wHash
|
00e7e7ffe7e70000 |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
71080c080e08aaaa,8040717173715180,00000669698e30b2,00000c3232cc32b2,000c303394b213b4,000412c8e4cc481a,000c30328ab23034 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.