Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14D8294336180313F0EA211C37BA12759B3778581976519A9C9BD934E0BC9E4FEF77609 |
|
CONTENT
ssdeep
|
384:Jq09IIcsPtOqQh0gbmon/Pas8v3AyvZ46DE:J1IIyqQh0gSS2TZa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a747f81278c238f9 |
|
VISUAL
aHash
|
002020200000ffff |
|
VISUAL
dHash
|
c5c7c7c7effc9233 |
|
VISUAL
wHash
|
203131710307ffff |
|
VISUAL
colorHash
|
010000001c0 |
|
VISUAL
cropResistant
|
d080000b332b2b33,2d2d565152647412,c4c7c7c7c7efeff8,00aa158aaca473b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Pages with identical visual appearance (based on perceptual hash)