Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17C443030A1839D33B1A7C0D0A370EF5B7395C39AD6174B0A57F8539EABCAD81EC15989 |
|
CONTENT
ssdeep
|
1536:e6GOTWckGKZ3jYzFjN1i8YC6DhbuUqK97N:HN1iHbuUF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b91ac7c7c33838a6 |
|
VISUAL
aHash
|
34008381c3c3d3ff |
|
VISUAL
dHash
|
444c3b3b1b13230a |
|
VISUAL
wHash
|
3f008381c3c3d3ff |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
205a546454578c4c,3b3b3b1b17332a12,000100030b0b0002,23c4c48414140300,ebcdddb99bbdcdcd,cdcc0f11941e9a96,0024697161691620,9c336143b3674e1f,c9a0e151476f4f1f,c285c7c6af2f5f1f |
• Threat: Credential harvesting phishing kit
• Target: Copart users internationally
• Method: Fake registration and login forms stealing user data
• Exfil: Data likely sent to unauthorized servers
• Indicators: Domain mismatch, recent domain, obfuscated JS
• Risk: HIGH - Immediate credential theft
Pages with identical visual appearance (based on perceptual hash)