Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12141EFB898989E374283E2F41B72679B23E9C355CA471B0657F8D34A5FE7D88CD00529 |
|
CONTENT
ssdeep
|
48:E7SIOFqk0NCZni/yGeHvTB0tayC5+FHivTuvj9FZnixG:E7j94k/yGePTB0taJXTuvjDk8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b131cece749b3131 |
|
VISUAL
aHash
|
ffcfcfcfc3cfffff |
|
VISUAL
dHash
|
649899999e9c6098 |
|
VISUAL
wHash
|
ebcfc7cf000ccc4c |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
649899999e9c6098,13e4a2c999d92588 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Found 6 other scans for this domain