Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C6A22271421C9939612385C8E276737A31EBA289EF4F13145BED13B4A7C9D92FC37458 |
|
CONTENT
ssdeep
|
384:udmB5/iYInSVy9ZEDPJ8sR/sTLsJ6s1KpTsums/GssYxsW5is9dsKE:Dy9eJNsmvKpllPjJtE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e63399669932cc99 |
|
VISUAL
aHash
|
e7e7e7e7e7e7e7ff |
|
VISUAL
dHash
|
4d4d4d4d4d4d4d28 |
|
VISUAL
wHash
|
c3c3c3c3c0c0c0d8 |
|
VISUAL
colorHash
|
060001c0002 |
|
VISUAL
cropResistant
|
4d4d4d4d4d4d4d28,a10000a0032c8893 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.