Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF22D9403812DC2691CF0EDCA6B6462951BD8741C697568DF9B183FA2BEFDBCC273860 |
|
CONTENT
ssdeep
|
96:adCjDS0C+QqtsKEp/LFVMMHVz7VMuKT8v++KARpQAFwLlXdK7l7aI7D64l9S:adCjEFK0DFF5k8v+ooP/pKlw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e4db62ca61ca61cb |
|
VISUAL
aHash
|
fde7e3fffbf3ffc3 |
|
VISUAL
dHash
|
314c0e3222266096 |
|
VISUAL
wHash
|
fde4c0f830383000 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
314c0e3222266096 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
| ID | Portuguese | English | Trigger |
|---|---|---|---|
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain