Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16FA3F030A050983311D3A7C5D778E32BBB91DA09CA57AAC156F0E36E1EE7D91FE23158 |
|
CONTENT
ssdeep
|
384:BAtgn/CuaedBTF+DTPeKrgHEdSHf/cO90j6FmIcTH9HHpce1usS8RcTscCu/qDW7:KgeifviHTk/QLF9BUkC8fK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c04cbf3b60921f6e |
|
VISUAL
aHash
|
00ff00000000ffff |
|
VISUAL
dHash
|
1fa0e4c8c0580833 |
|
VISUAL
wHash
|
81ff74600000ffff |
|
VISUAL
colorHash
|
0a200030200 |
|
VISUAL
cropResistant
|
98d8e0e0a0a4e4e4,f2004c08000100ec,50084d255a372762,1011e251470f3580,e0a4e4e88485ead0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.