Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T104E220B0D16DA93740FFD6C6A2A9577772D8815DDA030B4023FC67B913CACA9B913C4A |
|
CONTENT
ssdeep
|
384:UMyEgWaZaaaf8NWaZaaa/DhtaLcngLPSXaUtup8Nj+:UrEg9M5f8N9M5rhVycC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b616e9c949b63694 |
|
VISUAL
aHash
|
0006060000ffffff |
|
VISUAL
dHash
|
532c2c2ca30c0017 |
|
VISUAL
wHash
|
0006868600ffffff |
|
VISUAL
colorHash
|
32002000280 |
|
VISUAL
cropResistant
|
9818612931303180,00084d0c08061696,35db2c2c2c2ce3aa,064035c94b758100 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.