Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B8C1C71BB34133380A5B02AEBE8752EEAB37985863650F6591BC411E57854DCC33FF95 |
|
CONTENT
ssdeep
|
96:TfJq7kviz02oh0ICKskIQ5ubrMe2EJ1u4NSXx5w3xUKgkGsVMHwoFaYkeuK4rc8R:bJtiz02xICq5KrXp3KK50rMd7a4/Z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b929c6869b8cc69b |
|
VISUAL
aHash
|
ffc3c3c3c3ffffff |
|
VISUAL
dHash
|
869696929a0e9696 |
|
VISUAL
wHash
|
c3c3c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07000000000 |
|
VISUAL
cropResistant
|
869696929a0e9696,beb07471d9d2b0e4,e4b0f96969694858 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.