Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T170D16337E34933A509634316F10A8BEAD21944A8F7231D66A6BDC11C5BD0AD5CC7BBCB |
|
CONTENT
ssdeep
|
96:GQ2aJdM4cRCl6MXLCWspOA6mlDnr5BTw85r0mOmNtBt9V4ejv/Hp8C63i9:/M4mZ6Qr1vN9ye7/16S9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b80f0f0f120b1bef |
|
VISUAL
aHash
|
0000ffffffffffff |
|
VISUAL
dHash
|
f9b7141c1e32361c |
|
VISUAL
wHash
|
0000c3cfc7c3dfcf |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
36161c1e3036321c,fffde9f9e9f3f3ff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.