Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T126310E707004BD37034296D467A67B6AB785C197CA873A0459F983EE8BFAE86CD14162 |
|
CONTENT
ssdeep
|
24:hR/CfUV2dPjTN/+TN/0AOiZhgdF3Q8v2I3z91us7lWFNtB75hU1KGw3y8se:Tz4dPjTNmTNMo0JQu2gV7gFFTKe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dc2b372cd8996626 |
|
VISUAL
aHash
|
000000f8fcfcfcfc |
|
VISUAL
dHash
|
7f4c283220200000 |
|
VISUAL
wHash
|
000000f8fcfefefe |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
7f4c283220200000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
| ID | Portugués | Inglés | Trigger |
|---|---|---|---|