Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E0A2D8F0A244F92A1503C2C0E7B38B5F3367D682DAA707A693F5436EABC1DD4CC46169 |
|
CONTENT
ssdeep
|
192:aujfWUphBzC1iaJFQG+pK1+biw0d6GTVwbcgMl06itmZEnsAq3Wir2Z3oJOOdhQ6:auDPhBGDJbd6DPSOZ3ojhQGYrCT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec92936d67940cd3 |
|
VISUAL
aHash
|
ffffdfe3e1d1dfff |
|
VISUAL
dHash
|
c41036272727340b |
|
VISUAL
wHash
|
36ff9381818181ff |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
c41036272727340b,0b1ba50d9127213f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.