Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13372A372A144213F06E702C16F51B3CAA7F75546A2010D5C6EFC83580BDAE9DEF366B9 |
|
CONTENT
ssdeep
|
384:LOIadpgII1i2E/D+Qs3vta4slUPPu/B5LUE6PJdM:yIIIQ/6XY4slUPPs5Ui |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a903edfc9238d2d8 |
|
VISUAL
aHash
|
00000000ffffc3ff |
|
VISUAL
dHash
|
cec3c7eff42b3333 |
|
VISUAL
wHash
|
00200001ffffdbff |
|
VISUAL
colorHash
|
02000000181 |
|
VISUAL
cropResistant
|
f0002b2b333323c8,cccfc3c3ddefc7f8,22ccd46970b2324c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.