Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T112728933F148253F095206C17F55236DA366414ADA0A7AAD46BCC36C1BEAF0CFDB7646 |
|
CONTENT
ssdeep
|
192:cfxW5OYxp3pIIufxPUxYr1fRs0cCFe6SRaV8K9w7X/u2AjM2EjGFNkc2xum0XPKi:w2pZIImUSrtFe/R9X2dbJmOY1dM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec13ee11923d12ed |
|
VISUAL
aHash
|
000000007f00fffb |
|
VISUAL
dHash
|
c4e7c7e7f0d82723 |
|
VISUAL
wHash
|
00316103ff00ffff |
|
VISUAL
colorHash
|
020000001c0 |
|
VISUAL
cropResistant
|
d3f1c0d4a2a20000,0200272727232323,c4e7c3c7e7fef0d1,0000d429d4d4d4d6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.