Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1235141A1A0ACA9338183D0D277BA2F0972E0855AC65A2E04C1FCD2DD5FEFE44DC17295 |
|
CONTENT
ssdeep
|
24:hRF8Cc7WR2ztBM6yPHxWLpAudR2ni1M/b1TjMcg6DdNEl6ctfqGTjqg6P4kGopNV:T2a6jMdJm12nM20L+azXpwGKqG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce8c3133ceccdc23 |
|
VISUAL
aHash
|
0000383830380000 |
|
VISUAL
dHash
|
0008606460600800 |
|
VISUAL
wHash
|
00003838fcfcf0f0 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
0008606460600800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.
Pages with identical visual appearance (based on perceptual hash)