Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A3316351D140980B634381A06BB2E32DB305C652CBC34F282AB891BEF9CDCE4C6B5294 |
|
CONTENT
ssdeep
|
48:nes55+3uPYSRqWPZcRkdPADYFwe3Q4PXit7PuD:n/A3BSRqWSRkdFA4Y2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
83191d1f72d8f8e2 |
|
VISUAL
aHash
|
00007fff677f7fff |
|
VISUAL
dHash
|
51d2d4c8cdece0e8 |
|
VISUAL
wHash
|
00001f2f273f3f3f |
|
VISUAL
colorHash
|
07200088040 |
|
VISUAL
cropResistant
|
51d2d4c8cdece0e8,0303614105017140 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.