Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13441D0D7380028A6566388C8AF527F2FF9D6E31FC649C91428BC4296AFD7DB4F404CA5 |
|
CONTENT
ssdeep
|
48:SHup997Ixu9qaqW0bC1QQbcuBSZuBsZuBDdbZi9kY+gfG3couQsH:KuX9Mxu9qZQ1QmcuBSZuBsZuBDdbZi99 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc2e331b333399cc |
|
VISUAL
aHash
|
00181818187e667e |
|
VISUAL
dHash
|
88b0b0f0b0b0ccd4 |
|
VISUAL
wHash
|
0018185a7e7e7e7e |
|
VISUAL
colorHash
|
38000000e00 |
|
VISUAL
cropResistant
|
88b0b0f0b0b0ccd4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.