Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10CD2227828977A3EA183C7F6917517AFF287CA04DF63CBC246E043A95EC1D8ADE51049 |
|
CONTENT
ssdeep
|
384:fNjZ4PVqN6ye3TBCfvInhgCkJnP2tk790Yer:RZ8yNfvLJnP2tk79S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c76b96789469c392 |
|
VISUAL
aHash
|
067070207c00243e |
|
VISUAL
dHash
|
54c3c5c699c9d454 |
|
VISUAL
wHash
|
f6f1f1f17c00203e |
|
VISUAL
colorHash
|
0fe00008000 |
|
VISUAL
cropResistant
|
66686c7cf6f2f26c,54c3c5c699c9d454 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.