Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14CC2146C20901597D03B8AC2A03639FF9471938FCF29056676AA53AD3FF68D1F558C78 |
|
CONTENT
ssdeep
|
384:3ybgbUkzlgzl1ShYy5E2Du7TVROBDqLTV5tDoTMhoVupBfwhB:3ybgbUnShYytkuqLTV5tDKMqAAB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9616bb391cb97911 |
|
VISUAL
aHash
|
0e060e1600ffffff |
|
VISUAL
dHash
|
6cecece46495080e |
|
VISUAL
wHash
|
0c06041404ffffff |
|
VISUAL
colorHash
|
16600000002 |
|
VISUAL
cropResistant
|
9f9b9f9fadedcfc6,9e0c000c0f370c4c,7c6cececf4646471 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Pages with identical visual appearance (based on perceptual hash)