Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FDF2D6319AD92B33557343C1ABA767AB73D08284E2928E4293FD8B9D97CCD01FC75609 |
|
CONTENT
ssdeep
|
768:dt4SR5DMdX0WzPylzw0yyTtTPCRpI2Jlze81PRN:dt4SR5DMdXZzPyl7tTPCRvzeED |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92e9699292c9dec9 |
|
VISUAL
aHash
|
ff00202e2e2e0000 |
|
VISUAL
dHash
|
8bcfcdccccccc7cf |
|
VISUAL
wHash
|
ff21237e7e2e6001 |
|
VISUAL
colorHash
|
00000000180 |
|
VISUAL
cropResistant
|
2bdbdbbb8bcbdb2b,ccec2e8acecc6aea,99282bd2d3262665,263a73244d4cbdd9,9bcfcdccccccc7cf |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.