Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16472B737A108323F0DA252C32BD1375DF3B78081E615191C8ABEA25F5BD9E5EED3640A |
|
CONTENT
ssdeep
|
192:cbEVRs7EOFEd77YhuQyw3DIIu8DLMwZ3FZX6Jxqvm6x6fNa9f8WIjJZkTpkfI7dK:R5wTIIlR6xop+cCko5rgN8+DT0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e613ec911aed9269 |
|
VISUAL
aHash
|
0000000000fffbff |
|
VISUAL
dHash
|
c4e7c7e7ffc22723 |
|
VISUAL
wHash
|
0030212103ffffff |
|
VISUAL
colorHash
|
02000000380 |
|
VISUAL
cropResistant
|
f000272727230b23,b28282828a8282aa,a2a2a2b2a2a2a2a2,a2a0aaaaa2a0a0a2,c4e7c7c7e7cffff8,00802bd4d4d4d4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.