Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1361255348888653B0653E1D9EB70AB1FE2D1D146CD232F469AF4874C0FCBE61CC95799 |
|
CONTENT
ssdeep
|
192:scKoIRwHrBgYV3dIMnTjmDL3LO9kJAtU3b:PvIMnTjmDL3LOuJAtU3b |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fce396c2a9d0e0d4 |
|
VISUAL
aHash
|
ff8080c8c0e09e9f |
|
VISUAL
dHash
|
692a323212053434 |
|
VISUAL
wHash
|
ff80c8d888e09e9f |
|
VISUAL
colorHash
|
06600010040 |
|
VISUAL
cropResistant
|
692a323212053434,3c2c1f0f07273396,0f0303232323038f,3339391815267333,a0038e8f1f3e63e6,30381bcb8333b363 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Pages with identical visual appearance (based on perceptual hash)