Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B60261356048FA3B05C362F1EB3127EFA2A08282C9131B0697F8C3AD9BC6D5DDC32556 |
|
CONTENT
ssdeep
|
192:i1Rql4woJwbFCUwgO6tVUSYIUshqxH1hcyQ0bj7Y42sq:ilPJwX0jbjE4Q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
80d4f6d0d4d5d4d6 |
|
VISUAL
aHash
|
ff0009191903070f |
|
VISUAL
dHash
|
fcfff3f3f39bc7ff |
|
VISUAL
wHash
|
ff0009193f071f1f |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
fcfff3f3f39bc7ff,fffff8f9fcdbe3ff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.