Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B4B3C5FDA3285EBDE447C3D5DB61227A326D90A6D6420728C6FC4B685983C9CEC27CC5 |
|
CONTENT
ssdeep
|
384:pqZN76BbIaT/wiIvZVri+KIR4NdOZ443kiqZN76BbIaT/wiIvZVri+fqZN76BbIm:gElQL443kVElQ2ElQPElQoElQtTWEEZw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cca031f7543693d5 |
|
VISUAL
aHash
|
025979b0faff8018 |
|
VISUAL
dHash
|
c4b3b326621a3032 |
|
VISUAL
wHash
|
025979f8faff8018 |
|
VISUAL
colorHash
|
32038000000 |
|
VISUAL
cropResistant
|
8280110705408082,c4b3b326621a3032 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.