Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T123C16526F1EA275207234264A21277BDC316D0B4E6511AD93ADEC36C45B4A93DCF738F |
|
CONTENT
ssdeep
|
96:TvZxOfnSOrFK7f3CYGHX3QQV+a350aEZFHpYXVPbi0ehwUBWXYJq4Hcihh1:d3CYGnx0a35MZFSeDBb7H |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b06d656565316cd3 |
|
VISUAL
aHash
|
c3c3efcfffc7c7c7 |
|
VISUAL
dHash
|
96969c9e8c9e9e9e |
|
VISUAL
wHash
|
c3c3c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07001000180 |
|
VISUAL
cropResistant
|
96969c9e8c9e9e9e,055094b4aa2005c0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.