Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12D53C63EB480337344C792D1BB669B2BB2BC85C8D6139614D6F9C3480BE7C98D5766AC |
|
CONTENT
ssdeep
|
1536:z44TKecGRU9roYkw+7PPaSNNllPhTUnH4RrAmllFnCa0OelhGkQUfmV:BcGRU9roo0PPa2Pl8mllQa6hZQ/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c3731669db38c36 |
|
VISUAL
aHash
|
0600183c18180018 |
|
VISUAL
dHash
|
9c51f0e0b0b04832 |
|
VISUAL
wHash
|
46003f7ffefc8018 |
|
VISUAL
colorHash
|
38006008040 |
|
VISUAL
cropResistant
|
ffffff3f2fffffff,9c51f0e0b0b04832 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.