Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14B32A967F24833300B5740A1EB1343E8E739D0A8B7512F9265FF835C9A8869986F77D9 |
|
CONTENT
ssdeep
|
192:BPOaW0QZIB7C5yFfB6w6QJYswdcOpZehevU9HNgnu50h:tyOB+26wjQUhevU9HNgI0h |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3e131cd69d360cd |
|
VISUAL
aHash
|
783c3c3c383c3c24 |
|
VISUAL
dHash
|
c1c8e0c06040c0c8 |
|
VISUAL
wHash
|
7c3c3c3c383c3c3c |
|
VISUAL
colorHash
|
38002000050 |
|
VISUAL
cropResistant
|
c1c8e0c06040c0c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.