Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18982C8226245313E469702D26B51235EF3FA89C392061B9C85FC839DEBCAD5CFE7B644 |
|
CONTENT
ssdeep
|
192:cqH3NqYbwkSNIIXT8ZJDFf3z3fUfv/fMRiwhbZYCD0dhyxklL8nIxxx7L438+uUe:FbwXNIIj8J3+cRnghyxnIPUjAjj8Bt0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e713fc12ed126c91 |
|
VISUAL
aHash
|
002020202100ffff |
|
VISUAL
dHash
|
cccfc7c7c7efd827 |
|
VISUAL
wHash
|
002131712137ffff |
|
VISUAL
colorHash
|
010000001c0 |
|
VISUAL
cropResistant
|
64740d8b8b9baaad,4c2a09483a43b5b4,0f6a4a84b9ad26a5,a9abaaab4bd3b3bb,f080039007272767,cccfc7c7c7c7efe8,4102000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.