Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CC328671A1942B3B029362D0BBC5BF563192C354CAC56B4442FE83EE0FE7D79F90A165 |
|
CONTENT
ssdeep
|
192:QnQrT8Gl3LvFrjKY8j+30b45yt7EW2IM+6gCKmkxTuyxM2OqpXoJs6p:z8EL1jSj+30bxtojJxkmkpzOqpXH6p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c0903f6bcdb42ecc |
|
VISUAL
aHash
|
004466fef8e06000 |
|
VISUAL
dHash
|
088c9cd4d1c7cccc |
|
VISUAL
wHash
|
804ef6fffce16400 |
|
VISUAL
colorHash
|
38c00000002 |
|
VISUAL
cropResistant
|
088c9cd4d1c7cccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.