Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C351C81A7498701B0BA2335C3D12E7BD976341AB4B791F063054AE4FB8E2B178C051AF |
|
CONTENT
ssdeep
|
48:TfC0SRkhDUcBgt4X4C0aNWxaLCw+0k7/rmnRqccArORlsQ4Asau/k7/rmnRqccAS:TK0SyCIRjcfR3rD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
acc913d36dec4c92 |
|
VISUAL
aHash
|
ffffd3c3ffffff00 |
|
VISUAL
dHash
|
0249b69646400e16 |
|
VISUAL
wHash
|
f0fcc4c0f1f3d700 |
|
VISUAL
colorHash
|
07001001180 |
|
VISUAL
cropResistant
|
0248b69616620e0e,100c32b2b2300800 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.
Pages with identical visual appearance (based on perceptual hash)