Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18871ED3650847823029392E62B72672B73E3C395DE470B112AE5DB4D5FE3E5EDC96382 |
|
CONTENT
ssdeep
|
48:TzKU6+TF2rIDQ7tKvWrnC9I7IhSOIaTlGadZLVKjcsirT9yVs0Q8qMHhz:TNHTF2z5K+rC9/caTlGad/GIEhz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d90ba47233f3788c |
|
VISUAL
aHash
|
0018180c0040fe7e |
|
VISUAL
dHash
|
18f0f3d8e8a0aaaa |
|
VISUAL
wHash
|
0838383c38c0ffff |
|
VISUAL
colorHash
|
38006000001 |
|
VISUAL
cropResistant
|
18f0f3d8e8a0aaaa |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.
Pages with identical visual appearance (based on perceptual hash)