Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T115426215C3450704F773ADDDF6A3EB87A146460E91090AB4BBEC16A9E8DF6B423A07DC |
|
CONTENT
ssdeep
|
192:EeY3eYfoO7kR4YpMOuJ0kANIfoklNIJCkpNIRD/bNBoC4HDErepn4n:Ee1LOaMOMANolNkpNsz8HONn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cedbcd26b0b2b308 |
|
VISUAL
aHash
|
ff10ffff00001018 |
|
VISUAL
dHash
|
61711171354d3133 |
|
VISUAL
wHash
|
ff98ffff00000018 |
|
VISUAL
colorHash
|
08007000000 |
|
VISUAL
cropResistant
|
61711171354d3133,0101404323208101,0061613131213301,0111057171050101,35310d050d253233 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Found 3 other scans for this domain