Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18B11EF6880984C378282D1F467E4AA1E3685C683CE4B5B194BF8C79D2EE7E16DE450A5 |
|
CONTENT
ssdeep
|
24:hR/CB5O6Gkv9hwN9ugNOH69zH/VMDtxRmhk7GX7m:TewH2ahVMDj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8859337633d9cc66 |
|
VISUAL
aHash
|
00181819191b1b07 |
|
VISUAL
dHash
|
cff3b3b3b3b3f3ef |
|
VISUAL
wHash
|
01191b1b1f1f1f1f |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
c88abac0323388aa,cff3b3b3b3b3f3ef |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.