Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T186A3751075092477932311C7A0782B6BA1D3928EC68F84C5C7F957D607DBDEABC3BA89 |
|
CONTENT
ssdeep
|
1536:B3bL5WWrvh9A0B6WiHeAiHe1z6d+zo6UlQ1dItoeJ0HW3qwRVjF/ttBkyN0G:BjzX021X |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9148ee92e4ccf0eb |
|
VISUAL
aHash
|
ff0c000c0e0e0eff |
|
VISUAL
dHash
|
2158d8d8d8dc5c0e |
|
VISUAL
wHash
|
ff0e080e0e0e0eff |
|
VISUAL
colorHash
|
1e400008080 |
|
VISUAL
cropResistant
|
236b0029211636c9,51515527696b6e6e,4ef879690a3a8e2c,0000000c4d0c4d0c,d8d8d8dcd8d89c5c,a2a691d0ec6cd2a2,53e48586c26575b5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Pages with identical visual appearance (based on perceptual hash)