Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T147E1ADB2F5D5A93A2036C5D2B3AA1B27F1F0C55CC9C21666A3FC43E84BEBC57B912504 |
|
CONTENT
ssdeep
|
192:vaJawfzLQqmTBHbvZ8rQ6Hq4FZD/D8EepVS9jh:CJawfzL3mTBHbvKs6HnH/DJyS9jh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9212ececb1e1e5cc |
|
VISUAL
aHash
|
0c0c040c0cffffff |
|
VISUAL
dHash
|
3969695979362416 |
|
VISUAL
wHash
|
0c04040c0cffffff |
|
VISUAL
colorHash
|
06003000180 |
|
VISUAL
cropResistant
|
3969695979362416,b870f068686c3818,03041c0c2c9492b0,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
| ID | Portugués | Inglés | Trigger |
|---|---|---|---|