Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14F51DD6220473537022743CCA6A73B19B0D7C636FB863B019EF4829A5BAAD50BD2955B |
|
CONTENT
ssdeep
|
48:c4OfTNmTNMeZC6BSZSZS4QXH7aeIix8mzPl+yltBtrBzNZ0XZwH69T+65R/adwBC:c41ZC6BSZSZS4w5BtzNZ0XZb9z5R/adh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
87f0787e607e6078 |
|
VISUAL
aHash
|
803f3f3f3f3f3f3f |
|
VISUAL
dHash
|
61e0e4e4e66668e8 |
|
VISUAL
wHash
|
003f3f3313131f1f |
|
VISUAL
colorHash
|
06601000600 |
|
VISUAL
cropResistant
|
61e0e4e4e66668e8,0000482327180100,18cdac98c9c3e37a,cec6e36868f0b635 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Pages with identical visual appearance (based on perceptual hash)