Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16DC1DDF04099B63B53D793DCEB35DB6A76C1C140CA235A00A2E9C31E8ED6E18DFA7156 |
|
CONTENT
ssdeep
|
96:TS+LecX+kT8NO+R7p/743+U7p/e+y7p/Vl+l87p/l+77p/o+07p/c+77p/f+S7p+:GmD8j7pDg7pK7pS87pk7pi7pp7px7pKb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f0f02f0f0f98f0e2 |
|
VISUAL
aHash
|
0140ccdc0000ff18 |
|
VISUAL
dHash
|
0b80999800103010 |
|
VISUAL
wHash
|
81c0fcde0000ffff |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
0b80999800103010 |
Fake MetaVault page designed to appear in search results and trick users into visiting. May redirect to credential harvesting pages, malware downloads, or serve as a trust-building step before requesting sensitive information.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.