Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A9728522A520323F09C316917F6D5B4EE7A3854AA216075DA9BC939C0FD8F0DFE37255 |
|
CONTENT
ssdeep
|
192:cheOYtp0MFOyII2j2alXCbIfF4D38zH4Ns75Q25WyzVrysX/edyHHxEEPIwNXGjX:8+p0cII2flSEt4z8rf5d5nV+0x5m6x50 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8767d3907b452c5c |
|
VISUAL
aHash
|
00213121037fffff |
|
VISUAL
dHash
|
ccc7e7c7e7fec041 |
|
VISUAL
wHash
|
00213131033fffff |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
95d55c4d470f0dfb,ab97367262526ded,5555c2e2b6469496,e7e7efdffff1c08e,0000000000000000,cccfc7c7c7e7fff8,401ac1c1c0624000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.