Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B32AAF06185EAB302E3B3C1A6A5BF5B37D08349CA564B0652FEC7A90FEDD04EC22415 |
|
CONTENT
ssdeep
|
192:IzRtyOvddwbt1frvoFF0ZS3jzRtjOvddwbt1frvoFF0ZS3c:5Ovop1fDy0ZS3LOvop1fDy0ZS3c |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
857d7a00895ebf45 |
|
VISUAL
aHash
|
0100ff7e7f2200ff |
|
VISUAL
dHash
|
53c64acac2ca002f |
|
VISUAL
wHash
|
0100ff7f7f0800ff |
|
VISUAL
colorHash
|
38000000241 |
|
VISUAL
cropResistant
|
ff3f3fffffcfcfff,53c64acac2ca002f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.
Pages with identical visual appearance (based on perceptual hash)