Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T179E1A571806858274043D3E4EAB6EF4E72D2E656CA1B1A09B3F4D39DAFC3E90DD022D5 |
|
CONTENT
ssdeep
|
96:/Q6ldJvvRDopf/sxb68+duaiuth9PSbJUhZBHVocfpxvmJwNJMv/wpy9dHQ:/Zzopf/ObO5isnAUlpgAMvS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b18bcf3066cf303c |
|
VISUAL
aHash
|
ffefffe7c3c3ffff |
|
VISUAL
dHash
|
1c1c064d9e9e0006 |
|
VISUAL
wHash
|
e4e4e4e40303df80 |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
1c1c064d9e9e0006,26ca4a622474ce6e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.