Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14521E45450515C774223F1D59B62DB2832E08E46CFA7160057F6435D7BC1CA9CCA72CD |
|
CONTENT
ssdeep
|
12:hRwMy7FU6KxjdpeXQqUcuG/UiZAzpmDpNWrXMOkP1d1Sg7EtdoJDcWJDV5BYgNt1:hR/C6UuCqbaHDNccTNtVEU/DKszHm/e |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc38c3c30667679c |
|
VISUAL
aHash
|
ffcf83831f5fffff |
|
VISUAL
dHash
|
82333636b0b1418c |
|
VISUAL
wHash
|
7f818303031ff9e3 |
|
VISUAL
colorHash
|
07202000040 |
|
VISUAL
cropResistant
|
82333636b0b1418c,e370596939498912,0008323232301000,e971311999869b83 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.