Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DC5220A1E062A77B0237D1C266D6A77A70E0422DDC97163292FD43AC0BDDD55BD03E8B |
|
CONTENT
ssdeep
|
384:i/8o6Pv5o44XjUorM5XTgb0+5AVmRS8MKjuH4iuUDgPi8EqyZ3b9QOnn:i/8o6Pv5o44XjUorMBgb0+5AwRS8MKS/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
841c31a3f37c4de3 |
|
VISUAL
aHash
|
00000000ffffffff |
|
VISUAL
dHash
|
dcf1b030cce20c96 |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
06000000e00 |
|
VISUAL
cropResistant
|
3624e4f65cd8d81c,8228c6c6dcce2082,0c88ce56a00c4c92,ccf7f1f1f2b03030 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.