Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T131B196B64080863717C3C2D03B62AB1E7293C295EE87572D15F6978D4FC6E99ED1A382 |
|
CONTENT
ssdeep
|
96:TSutpXBUsUTpkTkek3kfIkeZfVQZVHOUrjmkSCK2PIKOlrUP:Gut/U51kTkek3kfIkutQ/HLfjK8IKR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ceac933982f992c9 |
|
VISUAL
aHash
|
ff317c703000283c |
|
VISUAL
dHash
|
1be3e0e2631058f9 |
|
VISUAL
wHash
|
ff3b7c7a3000383c |
|
VISUAL
colorHash
|
38400008009 |
|
VISUAL
cropResistant
|
1be3e0e2631058f9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.