Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18EB151F69291E73301A791E27A7AA7EB7B85C2C5DC53060106FD83DE4BFAE52CD22144 |
|
CONTENT
ssdeep
|
96:TK4G/0BH+HsiLgARsvZRv5ZRdAfYmZRAZr3hs54jplc:O4G6+LgTRvHRdAf5RKrRs5K3c |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f43d436d3a2d2513 |
|
VISUAL
aHash
|
00fcfad0d8f0f8e4 |
|
VISUAL
dHash
|
858c02363002884c |
|
VISUAL
wHash
|
00fcfad0d8f0f8e4 |
|
VISUAL
colorHash
|
08000030000 |
|
VISUAL
cropResistant
|
844e8b9a90818c46,f474e6f2b9a949d4,2c92989424c89c83,858c02363002884c,3470313f92925336,06d67e3935313534,2c2da12327a7aa26,6a6262b6372eab33 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Pages with identical visual appearance (based on perceptual hash)