Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D7D27E70E485AA3B06D38395FF392B7E639281C0D6535F0C12E8874F8EDAF46CD125A9 |
|
CONTENT
ssdeep
|
384:veyXsectbaA37IBPYU+A99V9hYyAMIHd2YHtCkSLKk/uK6:cfl37IFrXV9KMII5bK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d5027f20fc1e763 |
|
VISUAL
aHash
|
00187a1810ffff33 |
|
VISUAL
dHash
|
f1b0d2f2338e5767 |
|
VISUAL
wHash
|
00187a1818ffff37 |
|
VISUAL
colorHash
|
03040200010 |
|
VISUAL
cropResistant
|
828082c2d2828082,a9d2f2334db36767,dca49aaeb6d4f0b0,f0cc868e8c9ecc69,f0f1c08c8cc3c6f0,c9b1a9b2d2f2f233,31343435341a32f1,f8f8e64f05331715 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.