Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T169F2C63A53482A3DE503C7F8F6607779A27ED6ADC2278768F1AC01719382D95C8376D8 |
|
CONTENT
ssdeep
|
768:LjNMssEK5rxCGoykkgnaPvBAh3o9Mpt/ki:CIzkKh9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93686cc2c239c77e |
|
VISUAL
aHash
|
00000e6e7e7e0000 |
|
VISUAL
dHash
|
95695cd8cccc18cb |
|
VISUAL
wHash
|
40000e7f7f7f0f07 |
|
VISUAL
colorHash
|
13000600180 |
|
VISUAL
cropResistant
|
95695cd8cccc18cb |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.