Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T189C14FF11055AA37029393E273726B2B33D2C285CA871B0016F983ED1FEBE59CD53296 |
|
CONTENT
ssdeep
|
48:Tu1Y1ip4FcjNAmUYmbtQhTab4DB9GI3u+wlwgibDyIyfBJo3Cdu5SCxP1AXGxvRa:Tui1ivjmghfe+EwxP5yzXd2SCxdAKa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc3b0e6433dc699c |
|
VISUAL
aHash
|
003c183c00787e1c |
|
VISUAL
dHash
|
0360f0e80cc4f4f5 |
|
VISUAL
wHash
|
013c187e247e7e3d |
|
VISUAL
colorHash
|
38000030001 |
|
VISUAL
cropResistant
|
0360f0e80cc4f4f5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.