Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T137B182BA2015723F0AD342E2B7219F1A7392D588C18B0B5415FCD3AE4FE5E4BDC176A9 |
|
CONTENT
ssdeep
|
96:TZlfiS7w7D0D16ZCX4KIortUlStzAn4NVUTr1mxhm:VFi8SU1cKHtUlEzAnAVUTrYxhm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ccb333cc8c338ecc |
|
VISUAL
aHash
|
0100383c18180000 |
|
VISUAL
dHash
|
21006032b2300010 |
|
VISUAL
wHash
|
81003c3c3c3c0000 |
|
VISUAL
colorHash
|
38000038000 |
|
VISUAL
cropResistant
|
0202026272020002,21006032b2300010 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters credit/debit card details including CVV and expiration. Card data is captured and can be used for fraudulent transactions or sold on dark web markets.