Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T146826136B305213F06B742C36B51626AB3B644D6E302290895ECC39C1FDAD5EEF7B295 |
|
CONTENT
ssdeep
|
384:oVWbQ01UII5jVwqQ7vdcMpUfaDNniilUTfS//jG6+Cc+GmIAx8:oVWLUII5jVjs1LpUfa1lUM/jG6+Cih |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a243f518bf401ef9 |
|
VISUAL
aHash
|
002020200000ffff |
|
VISUAL
dHash
|
cecfc7c5dfef9f06 |
|
VISUAL
wHash
|
00607171030fffff |
|
VISUAL
colorHash
|
010000001c0 |
|
VISUAL
cropResistant
|
9f9f00a096124c0e,cecfcbc7c5dbef9f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.