Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11851CC6210873537022753CCA6937B29B1C3C536FAC23B019EF4C29E1BE6D51BD1955B |
|
CONTENT
ssdeep
|
96:c9ZC6BSZSZS41XI2tmNZJ9fPvAJoERTDdx:AZ7QII41DtWvOT53 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
87f0787f604f4664 |
|
VISUAL
aHash
|
303f3f3f3f3f3f3f |
|
VISUAL
dHash
|
e3e0e6ece6666ce8 |
|
VISUAL
wHash
|
003f37333333331f |
|
VISUAL
colorHash
|
06601000600 |
|
VISUAL
cropResistant
|
e3e0e6ece6666ce8,000054a9ab500000,0000419696410200,18cdac98c9c3e37a,cec6e36868f0b635 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters credit/debit card details including CVV and expiration. Card data is captured and can be used for fraudulent transactions or sold on dark web markets.
Found 1 other scan for this domain