Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D8D2B72480D1B66E96C313C653B08F1D3BFA43648B6742798DEA8B4E0DD2DD8CDF6985 |
|
CONTENT
ssdeep
|
384:CYOODQ+mX3dvIgalS8G+zmqYlH0ji87+sI9oiOpoiqRPw+1mq0g:RWX3d4U8Dzmq80BpYz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eb47b4340736963c |
|
VISUAL
aHash
|
0000000000ffffff |
|
VISUAL
dHash
|
c4c3c9cbc30e3b2f |
|
VISUAL
wHash
|
00e0706000ffffff |
|
VISUAL
colorHash
|
06000000180 |
|
VISUAL
cropResistant
|
4a6a94c7248ead84,945445c9baa555c8,92aaa09a9aa092a2,4c0f381323402f2b,c403c3c3e8c3c323,0100055353010101 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.