Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11931FFA020496E779243F2C4A39EBB0736C6C547CE5B1B0517F4D3ED4BEBD08D9A8145 |
|
CONTENT
ssdeep
|
24:hnC7vTtQAfZcuDfQTLPXSZr1oR3N9uENK4yBVHW/8VZP2DoDjipoDw904C5rb:KTS8cCtoR3HxY4+Y8zOivw904C5rb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dc66269933993366 |
|
VISUAL
aHash
|
0010181818181800 |
|
VISUAL
dHash
|
0034323232323204 |
|
VISUAL
wHash
|
f8f8f8f8d8d89880 |
|
VISUAL
colorHash
|
00002e00000 |
|
VISUAL
cropResistant
|
0000000000000000,b2d0c8f0b38696a6,0034323232323204 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain