Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10F82B4236184313B1FA301C12B45234EB3674081A60B2E69CDF9965F2BEDD6DFE77686 |
|
CONTENT
ssdeep
|
384:xWpTIIoOvlZSdZK85eKxEjl/x9Tlva4FhYp9hyF9tv8:xUIIoOvlZWZn5eljl/HTBVmyHe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec13ee9132ec926c |
|
VISUAL
aHash
|
0020200000fffbff |
|
VISUAL
dHash
|
c4c7e7e7e7d82723 |
|
VISUAL
wHash
|
0021310107fffbff |
|
VISUAL
colorHash
|
02000000047 |
|
VISUAL
cropResistant
|
aa5ada4664981555,7133bb2b2b2b23b4,acbb36d4d62476d4,5448aa8b8a12b3a5,e7e7eff80627232b,a282829282928282,a2a2a2aaa2a2a2a2,a2a0a0a6a2b2a0a0,c4efc7e7c7e7eff8,00942bd4d4d4d4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.