Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A551015193451D0EE0954616B390FF8A2397F405A3720A28FA46EAFF94CE494EEA33CD |
|
CONTENT
ssdeep
|
48:CijBFhfPLa8uHRz/OY9YYepRiEhNrYvYnwdxxwdJB2awdCzDtpKpzUbcyv40vIy:BvV6zGiYbbikrghSyKDt24bvvBvIy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed1612ed98b8866d |
|
VISUAL
aHash
|
ff0000fffbfbfbff |
|
VISUAL
dHash
|
b24849b2b262926c |
|
VISUAL
wHash
|
000000fff3f3c3ff |
|
VISUAL
colorHash
|
08000038000 |
|
VISUAL
cropResistant
|
0000000000000000,0842926262926218,0c3642030f47c3c7,40004840484c0048,49d4dcd4c4c4c645 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Pages with identical visual appearance (based on perceptual hash)