Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14E51B8224948AE2750D382C8A7B3EF3F23468390E6478F116FF9875F89CAC05CD65394 |
|
CONTENT
ssdeep
|
48:3KEY+5ykezYEu/K8AeDgZVXKZ5jBupiXujrTJ3PjbJJuUSgip:gOypM/me8KnM2ubJbbJJuXgI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
990997f6034aced6 |
|
VISUAL
aHash
|
0f0f0f0f0f0f0f0f |
|
VISUAL
dHash
|
53daf3f3983a3a5b |
|
VISUAL
wHash
|
0f0f0f0f0f0f0f0f |
|
VISUAL
colorHash
|
07200030000 |
|
VISUAL
cropResistant
|
86f4e66666e6647c,9e8c8686a0a0a087,abaab6b2b6a64e52,86ae5856435bd698,fcf8c2b2ba9a80c0,b4484992d29dd4c8,a99995dce0899399 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
| ID | Português | Inglês | Trigger |
|---|---|---|---|