Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T126D2F73690C5663F45E313BA7B60AF6FC2886259C7522E54B2DEC3ABDB82E11CC3154D |
|
CONTENT
ssdeep
|
384:tbr5IIoEdy2DIRzN0TPgwBySabP1eIyMCbwFcatjndSRLI6f67iPKNQJYqo0AQm+:tb9IICHRvwjLsCbwikGqQJYqo0xm+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
86a77974949ce1e4 |
|
VISUAL
aHash
|
0670777e76600000 |
|
VISUAL
dHash
|
d4c3c4ccc4c730f0 |
|
VISUAL
wHash
|
0673777ff7700018 |
|
VISUAL
colorHash
|
380030000c0 |
|
VISUAL
cropResistant
|
eee41c3efef8b9e0,d4c3c4ccc4c730f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.