Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FBC1857A5044457F43C347A17B35AB1AB7438280D7032B5860D8C36FAFE9F09CE6B6A5 |
|
CONTENT
ssdeep
|
96:TMMKh6KcuJ9mnwAhJZRla9IAtkDauVhj2DrGNiWyIKVoz+:okKV9mnLZRxj2vSiWyIKoz+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc6332cd3331ce33 |
|
VISUAL
aHash
|
003020583c3c1f05 |
|
VISUAL
dHash
|
8664aeb270603c0d |
|
VISUAL
wHash
|
427070fe3e3e8707 |
|
VISUAL
colorHash
|
31e00000001 |
|
VISUAL
cropResistant
|
8c008060608000c8,8664aeb270603c0d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.
Pages with identical visual appearance (based on perceptual hash)