Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CA72A8B27264B93F418783C43766EB2B32A292C4EA47132496FEC7590FE7E44DD16358 |
|
CONTENT
ssdeep
|
384:W6iH8nD+yFovARtBL2tRN5G4fSV1kTm18L5sSI9uzrq5j7fP3Tiv8nD+U:W6U8nD+Ijess0BO5sSaHjb+8nD+U |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d9a4a091ce8fb6e8 |
|
VISUAL
aHash
|
ff4000381c0e0800 |
|
VISUAL
dHash
|
1694a671709a9a40 |
|
VISUAL
wHash
|
ff45103cfc5f0a28 |
|
VISUAL
colorHash
|
30600200002 |
|
VISUAL
cropResistant
|
2020243a72647408,1694a671709a9a40 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.