Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10943E535A0C02B7384D393C5B796DB2BF3D890C8E106C26592FAC35817DDD88D97AB99 |
|
CONTENT
ssdeep
|
768:Az2e44uWydEvR9o90IUb7gMt4vwknCSQwXk7wIUWvq12XPtvQQgfM/S:Y443940LDCQSPIU8c46Qgfz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc3331e69c33cc36 |
|
VISUAL
aHash
|
0600183c38380018 |
|
VISUAL
dHash
|
8449f0f0a0a04832 |
|
VISUAL
wHash
|
46003f7ffefc2018 |
|
VISUAL
colorHash
|
38006008040 |
|
VISUAL
cropResistant
|
ffffff2f2fffffff,8449f0f0a0a04832 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.