Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CF627427E34D33B40B570125E7130BBEDB3BA428B61D01A9295DC21C9ED09AD8A7B767 |
|
CONTENT
ssdeep
|
192:Zt7cALiq9b7EeCd6vLLYPWMy/EQjFdRlg/ZghRvx3+AwaT54H:QALiq9nSgLTz/jBv4AJ4H |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b84f4f631c6598e4 |
|
VISUAL
aHash
|
0000ffffffffffff |
|
VISUAL
dHash
|
040610361e9c16b4 |
|
VISUAL
wHash
|
0000c3dfc7cfc3cf |
|
VISUAL
colorHash
|
07000000000 |
|
VISUAL
cropResistant
|
0616b6961c9e06b4,0000200606200000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.