Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13802A232B044BA3F16E343E57B35C729B3D38640C74B0B6550F8835D4BE6D0AEC21A89 |
|
CONTENT
ssdeep
|
192:/mvZssCSR7qwJ91yJOAEyUsFw7j2+SolGpO7JY:+vZssbR7qwJ2JOAE2w7jPPlGx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c87bc4e463942fc9 |
|
VISUAL
aHash
|
b000181ca9007e70 |
|
VISUAL
dHash
|
614173694bb2b6d6 |
|
VISUAL
wHash
|
f160183db918ff58 |
|
VISUAL
colorHash
|
30600010000 |
|
VISUAL
cropResistant
|
dac37c3cbaf1c2e1,614173694bb2b6d6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters credit/debit card details including CVV and expiration. Card data is captured and can be used for fraudulent transactions or sold on dark web markets.