Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D124C62E2304E23D3247C2ADEA5176B5E38F7D6AD91F89A5C2FC9647DA5ACD1C503E00 |
|
CONTENT
ssdeep
|
3072:GMuA6L3VxStJE/ohhWVaY1aYbzaYZfaY1aY8eaY8gaYfoaY5mWaY5GqNS:GMwx2hszlu8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b801bb64fbe2509d |
|
VISUAL
aHash
|
ef0318180000ffdf |
|
VISUAL
dHash
|
9f3b31753696333b |
|
VISUAL
wHash
|
ef0b1d181000ffdf |
|
VISUAL
colorHash
|
16c08008000 |
|
VISUAL
cropResistant
|
9f3b31753696333b,82008855516800c0,626ac6d6e4bcd97a,8be138fb79f0b2aa,ce4a88595988488c,80b0b0b0b0b0a4e6,9f3e3a319174b696,6761f8f8f8b8b838 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.