Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FB03F9528988270B45931289BF42D32BD29950DCF32583C355DBC3EE14D8B45EEB7ABA |
|
CONTENT
ssdeep
|
768:qsMy97++XoZRIoT0BrW6UpOHs71Egu0Uw/3/id1xC7c0C:qsMy9++YZRIoTirW6UpOMOgu/ivid1xp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc077f0e001c9f9e |
|
VISUAL
aHash
|
0000ffdfdfffffdf |
|
VISUAL
dHash
|
2c0f3ab3b3333333 |
|
VISUAL
wHash
|
0087874f43c3c383 |
|
VISUAL
colorHash
|
07200030000 |
|
VISUAL
cropResistant
|
00202828282820c0,2f3bb3b333333333,0030c0c8c8000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.