Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17DF1B72B43052B3A02520345AE1D63FBC716405D92224B7E7BE9C51DBBB2A1D8CB3BD6 |
|
CONTENT
ssdeep
|
96:JEWWagi/dSxMRREuima9nHGR8z2w+tEyg9EgsyZH13b0p6/7xo6qtGN8JPnS5fmO:J+t6dUM0fGFxEyg9Eg5VLpD0jsHJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ea6e9531b41e616c |
|
VISUAL
aHash
|
006161016161ffff |
|
VISUAL
dHash
|
4fc3c565c7c37814 |
|
VISUAL
wHash
|
00e1c181e161ffff |
|
VISUAL
colorHash
|
01001000180 |
|
VISUAL
cropResistant
|
4fc3c565c7c37814,3a72d5d999599896,5551dc58d93aaeae,4c4cca34b65549e9,ab74742b1a2bb69d,de2626dad6b6beba,d4a0829e8ea2a0cc,36c7c3c5e5c7c37a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.
Pages with identical visual appearance (based on perceptual hash)