Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10EE12F301098AE3BA9D781E5A3F5A70F30D6C342EA8B530096F8839D5BC9D94CE51AA4 |
|
CONTENT
ssdeep
|
96:kz1dBkl6YrqCjU7yX4V+TJQkRq46O3WsXUvc:k/OjqCjCodlQyosWsXUk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3080c0ce6f3f3d9 |
|
VISUAL
aHash
|
0000ffe7e7e7e7e7 |
|
VISUAL
dHash
|
abb3084d4d4d4d4d |
|
VISUAL
wHash
|
0000cfc3c3ebe7e7 |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
000808080c4c0089,0c4c4d4c4d4d4d4d,ffeff3b3f3b3cfff,419024b2b2b24c31,419024b2b2b24c31,419024b2b2b24c31 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.