Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D8022AA0C8B5D6B714D361B4D3752ED53FC1934282670E1453F99349BEAADCACE23938 |
|
CONTENT
ssdeep
|
96:TwJLidPIM4PHWR4MV57wcLJiJ/JEJpJOJLJAJFJpJEJoV57wctKm:YLHeUIJiJ/JEJpJOJLJAJFJpJEJAUAKm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f94f134813875b4e |
|
VISUAL
aHash
|
00fbf8ffc0c0ffcf |
|
VISUAL
dHash
|
e11702b295959b9d |
|
VISUAL
wHash
|
00d1f0ffc0c0ff4e |
|
VISUAL
colorHash
|
07401010000 |
|
VISUAL
cropResistant
|
808082c2c2c28080,9313629695979b9d,e9c1236397176222,1c3d4cd6699d8503,981f3ba1c5c5b909,0f4e4c4e0616c667,41694d6c5e5e7e3e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Pages with identical visual appearance (based on perceptual hash)