Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A7027771D054ED2F8642C2C8E3573296B24AC18FCB570348A7E58739EDABD97EC112E5 |
|
CONTENT
ssdeep
|
96:Tm+11Kq537BR4uc6gFB6erAr96SjRV5m0SOq2aGyAW6VHLtrhZVVN5+:6+1Kqx7b5XerAISdJaGyA3rhB+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
da5ad88d8585a736 |
|
VISUAL
aHash
|
f8c8e4f8ccfdffef |
|
VISUAL
dHash
|
5129295119411018 |
|
VISUAL
wHash
|
f8c0c0f8c0fceccd |
|
VISUAL
colorHash
|
07003000180 |
|
VISUAL
cropResistant
|
5129295119411018 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Pages with identical visual appearance (based on perceptual hash)