Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14162A831B609353F07A706C26B52239E63B6C186D1112B1885FD93AE0FD6E0DFE3765A |
|
CONTENT
ssdeep
|
192:cDvpzsqYDpjyIIgImx8iqruzg/0Fl10o8irnbfoXf1mo1s561:28p+IIgIq8iqC8/0Fl1uhm61 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8263569d1cbbf451 |
|
VISUAL
aHash
|
002020007fffff00 |
|
VISUAL
dHash
|
e6c3c7c7f80083e4 |
|
VISUAL
wHash
|
00716101ffffff00 |
|
VISUAL
colorHash
|
020000001c0 |
|
VISUAL
cropResistant
|
6912963ddddd2ded,2d694b9bddac0a4a,23270445551d0d25,f000419616160000,84e7c3c3c5c7eff8,801da0e2e2249404 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.