Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D2915F2050952D37628396D8BB709F0F73A5C6D1CA130A0567F4C7AE5EDFE9ACC11292 |
|
CONTENT
ssdeep
|
48:GdK8rZpC9NXOsEfjSGvE0kzRQtF0Ap4DHxNoEcYDs0Asj8Mfqaan6y+GXa0sODxE:L89w94feIzbyxOTSK60ayMZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b7731c6236591d62 |
|
VISUAL
aHash
|
00ffffe7e7ffffff |
|
VISUAL
dHash
|
400c504c4d204c36 |
|
VISUAL
wHash
|
00c3cbcbc3dbe383 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
090c324c4c204c36,0000000141414080 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Found 2 other scans for this domain