Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B16322E2B2590C32423FA3DFD7C6B66B7071D14DE1824661F2FA8F3836CAE617191225 |
|
CONTENT
ssdeep
|
1536:zVTe+jIVZ00e0ete8le0LMHms+NyeEGLc+OaPMmsKKeQe5jE1xCMSQb1kPvXgGeu:z80iS7a/kt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
be3c60630f61613f |
|
VISUAL
aHash
|
00dfffbfbfffffff |
|
VISUAL
dHash
|
b438387068002020 |
|
VISUAL
wHash
|
0007070f0f4f7f01 |
|
VISUAL
colorHash
|
07000030040 |
|
VISUAL
cropResistant
|
3838307860002020,0000048080808040 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.