Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T171629430D3085A3C626F87F0E1680A6D364ED29EC6D37614E7AD1274F4F7AF6C854A98 |
|
CONTENT
ssdeep
|
192:0gvM8LtXdMjfPAYtxKtYIlZryJ+6Av6QUswM5VIhDMP5Q+K25rlUEJipCJixJiZ3:TMjfYYitYIlZra/Av6QUsXVy2Hx3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c992ce633723373 |
|
VISUAL
aHash
|
1818181820181800 |
|
VISUAL
dHash
|
31b3b2b0ccb2b048 |
|
VISUAL
wHash
|
191f3e7e7e783800 |
|
VISUAL
colorHash
|
38000180003 |
|
VISUAL
cropResistant
|
31b3b2b0ccb2b048 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.