Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19B5395B0B18A79B78462A3C0A7176EB373DC5145E351CF0483F9EB891ACAC54DC3AE65 |
|
CONTENT
ssdeep
|
768:x44QdPQdX6O6IeUkwhFp/ud0AEM1m2PVZakRP5ze3RUfnWRkCaxE9QPDs6:x44QdzO6MnpWNfjfRP5q3eWu1xE9QPo6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec394d934d656718 |
|
VISUAL
aHash
|
00c381c3ffffffc3 |
|
VISUAL
dHash
|
cc1b0f070fcc0f27 |
|
VISUAL
wHash
|
00c38181ffffc3c3 |
|
VISUAL
colorHash
|
0f200030000 |
|
VISUAL
cropResistant
|
0f1f0f070e4c0f27,a2001e3f333200b2,014686b2b2966681,730e8bc79696a66f,410ba49496a21045,6d75363252c9cbe3,23637b73725a775e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.