Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12B41996071045A770653A7C4B3B6D74E72C183AAC6530A0153FE837E27D6E08DD2A5B4 |
|
CONTENT
ssdeep
|
24:hnCFZuDfgygVSHuDfiHjcaEOH3pPWzPWkDGNa7hKDrR0ie7vd7/sHWCWAFNs:GZCbC6HjcaTCDG4YrR0iqvdjstFq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b131cececc933364 |
|
VISUAL
aHash
|
cfc7c7c7c3ffffff |
|
VISUAL
dHash
|
1e9e9e9e9616000c |
|
VISUAL
wHash
|
00000000033f3f27 |
|
VISUAL
colorHash
|
07402000040 |
|
VISUAL
cropResistant
|
1e9e9e9e9616000c,6a7aaa923824a820 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.
Pages with identical visual appearance (based on perceptual hash)