Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12E41F1508155D81DB4A6D3E5FDF42B5F0251C357A70308A8A3F4A27B69CFCE88E927C8 |
|
CONTENT
ssdeep
|
24:h29vesjfcHZd+KFhOcHZduw3ngd+2aptaFK+5ReSCN+5ReENWp3+5Rer59NZ+5gZ:AejhcQptaFP4S54E0pa4XCbMP1+S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
891ef62944767969 |
|
VISUAL
aHash
|
003f19393909ffff |
|
VISUAL
dHash
|
be7b73f3fb9b5b00 |
|
VISUAL
wHash
|
001f19390909ffff |
|
VISUAL
colorHash
|
06200000180 |
|
VISUAL
cropResistant
|
fa73f3f3db9b5a00,8080a0a1a6a6a140,481679699628a1a2,c70f1e9eb9f97c3e,b20f717186696995,4bb4f4aa82b4a945 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.