Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19FB1FC60E0689C334467C6DAA6F8872B23E18619DB130609D7F8C75E4FCFD41FE1A9A4 |
|
CONTENT
ssdeep
|
96:a33e3MRfH5tPuXuy/STSlJkuXmNSTuR5SSULkSVSjZuSTd16g9shzY1SO:a332M9peJ8PuE9rqVO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eca59212cdcb934b |
|
VISUAL
aHash
|
fff3f3f3f0c0f0f3 |
|
VISUAL
dHash
|
9646866646a623c2 |
|
VISUAL
wHash
|
fff3f3f080c080f0 |
|
VISUAL
colorHash
|
06600018000 |
|
VISUAL
cropResistant
|
9646866646a623c2,8f187a3430301c2d,2466c70f1d834191 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.