Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F5416579A080A6371693B1F2B3212704A7F18192D9131708E5FA93FE9FB1D1DC9236DB |
|
CONTENT
ssdeep
|
24:hR/C2M1V339UJO8GCAj5ohrPH8wEdBOfoz99RXGGnYn1bAGYN9uu1LhtQNeFo:T8jCDK5WrmiQDRXhYnpAdHfhWNWo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c31c7ce316c9b66 |
|
VISUAL
aHash
|
001818183c3c3c3c |
|
VISUAL
dHash
|
8669f1b269616171 |
|
VISUAL
wHash
|
003c18193d3f3f3f |
|
VISUAL
colorHash
|
30601008000 |
|
VISUAL
cropResistant
|
4c13e3c999d0f0e0,81a8c3c4d6aec672,8669f1b269616171 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.