Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11DA2A417934477AC0E620748BE2547FFA76DA4DCF22749E678EBC0781E908489937EC6 |
|
CONTENT
ssdeep
|
384:qiI5A7L5EcTs9LIvd39kibc7FYYl5zMpGYJaVd:7I5+pTs9udMSYl5NYcb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e59a99676b14174a |
|
VISUAL
aHash
|
ffffffe3e0e0c2c1 |
|
VISUAL
dHash
|
90165887878e8692 |
|
VISUAL
wHash
|
60ffffe3c0e0c0c0 |
|
VISUAL
colorHash
|
0e400000180 |
|
VISUAL
cropResistant
|
149f5887868e8692,59bcfe7efcfc7838,00000428b9994080,91979b1b1b87f133,9f9f1f1f1f9fdfff,8617130303030f3f,790f9f9888030000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.