Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11D1233666218B57A0AE781F71631439F22F8D68DF92307992AF4C36C0BC2DC4EE37655 |
|
CONTENT
ssdeep
|
96:TSqBqUPk1Kg8+jFNbAhNuZc3FAo0ZjYNU8q7qyyANqHgXCBPMVtTjk6Dc:GWzg80NbAhNuOwOa8eqCU3BEzm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d669699683966d92 |
|
VISUAL
aHash
|
0000003c7e7e7e7c |
|
VISUAL
dHash
|
617103c4d8e4f4c4 |
|
VISUAL
wHash
|
2010007e7e7e7e7e |
|
VISUAL
colorHash
|
02006000600 |
|
VISUAL
cropResistant
|
6078006466727ac1,82c2020959c94901,0000000501050505 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.