Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CA5203609C42D923525292E0AB716BAF33C1C342CA974F0167FC539EAEDBE52DD33195 |
|
CONTENT
ssdeep
|
96:TpzBtJGuXIjJLCKwoEbUU2GWG9JunB6Jh4/tc/VfA33LTyo59WHW84qx01q09tQj:FVGucJL0oVRS6nTC/VyTH2neozRwkKg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9f5160551fc6d05e |
|
VISUAL
aHash
|
0080fd3d08ffff9d |
|
VISUAL
dHash
|
c43dad7971702521 |
|
VISUAL
wHash
|
0000753c18ffff9d |
|
VISUAL
colorHash
|
07000e00000 |
|
VISUAL
cropResistant
|
808080d0c0808080,15b9e97970dc6121,d6f66be4e6c68efe,03c4c0c0d4031000,e9e96133aab47564,1b4f2a33f3575333,cc4cd9f1bbb7bbbf,ec7c666666646465,0e06c7636307cccc,4d4e4ec36dcc8c0c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.