Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T138029E9C2520543281839DEB2E77620E62CDD205C94ABAD16FA943EF1DD2ED1D80F74F |
|
CONTENT
ssdeep
|
48:bm9yzMnsjxqVKGMns0ug3XQ86+pLHDEjE0EjE6+Y9uEjEO9YDsrdZKUOGEjEgIE6:oFS/FXjKuGYrdHOKJv7/8hTvH26g2O |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93962ec16c3cd16e |
|
VISUAL
aHash
|
00ffff00407e0000 |
|
VISUAL
dHash
|
98cccc38c8d844c4 |
|
VISUAL
wHash
|
66ffff0c5a7e0000 |
|
VISUAL
colorHash
|
32208040080 |
|
VISUAL
cropResistant
|
f1cc7bd9c639d8e0,f8e08cb0d4c8f870,98899b1b0aabe736,98e08092da4ca098,32b4945454149434,98cccc38c8d844c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.