Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F4F29623908B692F03A3D6D4A6213F19F3918119C92A4E75E7EDC74FABC5E01DDB3294 |
|
CONTENT
ssdeep
|
384:z44O9lVOoRYjytC69fKBhlftplRLaPTj3:z44ONOoRY2tD9fKPUTL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946ab1b363339663 |
|
VISUAL
aHash
|
0c7c3c1c003e1c3e |
|
VISUAL
dHash
|
c8f0e4a0d0f0f8f4 |
|
VISUAL
wHash
|
0c7c3c7c007e1e7e |
|
VISUAL
colorHash
|
38003000040 |
|
VISUAL
cropResistant
|
8c191b9bed8e4acc,d198dc24233c7519,78726222a2a2a9a9,c8f0e4a0d0f0f8f4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.