Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T100C1635962595E7FE01382E9E382773A22D193C9D7894204D2FE53BC46C5CCCED3B594 |
|
CONTENT
ssdeep
|
96:CV3Hncp0lXlNsHs3s/uYQ4EWUkDivjYeF7p7C5j0:gcGl1NsHs3s/uYQfn210 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ea94916a6e95b9c2 |
|
VISUAL
aHash
|
ffffffc181818481 |
|
VISUAL
dHash
|
b039152b2b0b5c5b |
|
VISUAL
wHash
|
ffffff8181818001 |
|
VISUAL
colorHash
|
06003008000 |
|
VISUAL
cropResistant
|
b039152b2b0b5c5b,c1053d4d214f7e70,3ed9db1ad8cad231,21c10d334fbd71c3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.