Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17D81A832624418BB920F4AD6B636776F35E7839ECF23151432FC87A48BD9C99DE2A054 |
|
CONTENT
ssdeep
|
96:TmpNsIt4ChtdxYGjGW5QisZQZ+IZOaZVgdZsdZ3ca4+rF8LZsUoDO:6ByCh3me55QfM+k9Vgbsbe4us76 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3b93c7ee0f87060 |
|
VISUAL
aHash
|
c0ee7ffff0f0e040 |
|
VISUAL
dHash
|
095ad0c2c2404080 |
|
VISUAL
wHash
|
c0ee7efff0f06000 |
|
VISUAL
colorHash
|
38600030000 |
|
VISUAL
cropResistant
|
095ad0c2c2404080 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.