Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1547156127045742F021366E2F2A35B12F2A19045DE266A06D5F9CD6E4FF6CB1DA133BE |
|
CONTENT
ssdeep
|
96:T+OrYBnpx+40Z1JYTw8Y1A5Jf8YwFYtYXoY9s4huKJIm5R555:hYBrL9w/i5iFYtYXp7u2zD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
810ce7f88c238f9f |
|
VISUAL
aHash
|
1f1f0f1f1f2f6d3f |
|
VISUAL
dHash
|
b4f8fcf4b4dbdb64 |
|
VISUAL
wHash
|
1f0f071f1f2d003f |
|
VISUAL
colorHash
|
06600000080 |
|
VISUAL
cropResistant
|
b4f8fcf4b4dbdb64,0515abb7ce38f0c4,5f1547870f6b4b97,e7873bcbc39f7ef2,ce162f6f49959211 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.