Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10DC1D9B09086AE3701D782D1EF766B9FB3C486D0EA434B0947F4D3588ECBE5AED56460 |
|
CONTENT
ssdeep
|
96:Tt38HvATJJoaHj9gWSIi2MQF3S7io2GLJ55yF5v4ZdhrE1SkKDV:B38HvmJo49gaKb5y/v4ZdhrgSkKR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d34d6b1e618c0bd6 |
|
VISUAL
aHash
|
0000207ebc3cffed |
|
VISUAL
dHash
|
7348489a7c7db9d9 |
|
VISUAL
wHash
|
0000207efe3cffed |
|
VISUAL
colorHash
|
03001000030 |
|
VISUAL
cropResistant
|
8282c26aeae28282,4c488abc7c75a959,c4d29bdba892b8d0,92922eda5a295874,7348489a7c7db9d9,616d6c5c3e7e7c7c,e2d2d2f0f1f0b66c,a94b6e32f3535333,75b2b2b2b2b2b2b2,1f63b0baa2b222a2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.