Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10CE21A6033198D7E248F46DE9323620233A34458F9A37254D6F9D79E1E97CC4D8B9AE3 |
|
CONTENT
ssdeep
|
768:eJemSCxoWLkL1jgAWKlbNwevxVmwns+sR6x6sKJ:eJebjgAjb+wnsmxWJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b9998e64648f7135 |
|
VISUAL
aHash
|
bfcfc3cfc3c3bfff |
|
VISUAL
dHash
|
231b1b1b17176226 |
|
VISUAL
wHash
|
9b83818181ffb1c7 |
|
VISUAL
colorHash
|
0700060000a |
|
VISUAL
cropResistant
|
231b1b1b17176226,0111253333310901 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Found 1 other scan for this domain