Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T198418D31748C292B47D6A34D3A61A73E5397C1A69B171F0562E0AB0F9ED7E06CC402DF |
|
CONTENT
ssdeep
|
48:D0HUNCn5ilX/fmTJCnyUR/Wvx4AF4lm2ztn:DmarP23Q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d7dd04f632191b32 |
|
VISUAL
aHash
|
00ffffffffff0000 |
|
VISUAL
dHash
|
0c0028300c0800c4 |
|
VISUAL
wHash
|
00fffefee4fc0000 |
|
VISUAL
colorHash
|
0e0000001c0 |
|
VISUAL
cropResistant
|
00102830080c3000,0088404d4d408800,0000203232000000,02c4c4d4ccecc402 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Pages with identical visual appearance (based on perceptual hash)