Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15AF153958078CC7952834AF4E7F2B24B3660FF478A475E49D691D22938EEC68DC2FD14 |
|
CONTENT
ssdeep
|
192:8QPzhk3do2TsfOZdD1pDItEVw1Ojh++emA27RVzTmknQXFg32sRPzvT1OGHH0RTt:xzhe/gknQXFGJOPxFv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b11f1ee0e834b34b |
|
VISUAL
aHash
|
0f0f0f0f0f0f0f0f |
|
VISUAL
dHash
|
5adbdb9b9bd89b5a |
|
VISUAL
wHash
|
0f0f0f0f0f0f0f0f |
|
VISUAL
colorHash
|
06000038000 |
|
VISUAL
cropResistant
|
888c8c8c8e808480,b139787928395bd8,cab63a3ce6ebf2e2,087433e4f4f36418 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Pages with identical visual appearance (based on perceptual hash)