Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11942EDB1D091AE3B85B3D2E292758B2F71D15188CA130B8593FC839DAFCADE4FC01186 |
|
CONTENT
ssdeep
|
192:XbAqfTh/7fYCNfNFn7ltLU6cU67zyQ3gnIJL8C0O+NaBAKl:rzfvNfv7TLi12+QcAKl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6c9292926d6d65 |
|
VISUAL
aHash
|
fd9fd191ffffe7e7 |
|
VISUAL
dHash
|
2b3627232c3b4c4c |
|
VISUAL
wHash
|
818f819187c3e7e7 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
2b3627232c3b4c4c,1f3fbdcf8f9f8f7f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.