Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10581527064252067134B0EEAB8F53B0E30ABC31EDA47181827EC93D55BF6EF8DC29664 |
|
CONTENT
ssdeep
|
96:TqZeEMa9B4xke4Nbt6lS4I0sjM+3r9Wq7Vm9r9bi9iGM:2eED9VNYlSuyv79Jc9r9bi9o |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c3332cd1dcd9836 |
|
VISUAL
aHash
|
02041e1a1efbfa00 |
|
VISUAL
dHash
|
565cb0b2b2b2a6ac |
|
VISUAL
wHash
|
02041e1e1fffff04 |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
b2f2b0333380b286,565cb0b2b2b2a6ac |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain