Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13F924F713153297B918B83F3D869130FA0B0C789DA971515ABF8830D9FDAE56CF063A9 |
|
CONTENT
ssdeep
|
384:Fi8C4iAYufOhZBX8hCrOF3MkET0mD74GM+bScxrynS1rH6i2kQEVU30smevxGCBX:Fij4iAYufOhZBX8hCrOF3MkET0mD74GE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8b1d3c3cc3696c36 |
|
VISUAL
aHash
|
0808017f7f01011f |
|
VISUAL
dHash
|
f3f9f3d8cc9333f3 |
|
VISUAL
wHash
|
091f017f7f03033f |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
701a0c8080130604,539392c68a920204,74c6c6cf8a92060c,709b83c4d0030604,709a2983c1682010,86cccc60c8121206,f3f9f3d8cc9333f3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.