Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1317220227584653F0BD743CC7E60A7A9A3D34197CB1A1A0122F58B1F8BF6E82ED1116E |
|
CONTENT
ssdeep
|
384:0af3XL3ltnSCo5O9kueIG9jug+w9CuTFWl3ZunjhPszbbkHK:X3XL3HBo5O9kurG9ju/w9CuTM3mjW3+K |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b416e9c96b38c63c |
|
VISUAL
aHash
|
de000604ffffc3db |
|
VISUAL
dHash
|
38cccccc4d002b2b |
|
VISUAL
wHash
|
06000604ffffc3df |
|
VISUAL
colorHash
|
0e002000180 |
|
VISUAL
cropResistant
|
03009039343000bc,e28eece09a33a682,490c1fc03b2b2b2c,0022c4c4c4c41100,fcfccccccc9c4c49,7f7fffff7f7f7f7f,6dffdbffb6ff6dff,ffffffffffffffff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.