Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A4712DF0F0907237025386E8F75667A9B3C6816ACE4A0E0023F997994FFBD53ED0240A |
|
CONTENT
ssdeep
|
96:T9+xgt8CQHYjOJHzNCDYlibWOMj9MuzA6eV:BGgFjOhzNCDyoc9GV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b33b664c191b0de6 |
|
VISUAL
aHash
|
00ffef0cefffff00 |
|
VISUAL
dHash
|
4d0d5a5c5555084d |
|
VISUAL
wHash
|
00e7cf0c4f7ef700 |
|
VISUAL
colorHash
|
07200008048 |
|
VISUAL
cropResistant
|
4daf585c55550c0c,0084606979850000,39654c4e784c642c,0000000000000044 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.