Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14BC11C3A3005657F03A363E67A384B4B62838162CB470F6531F1939E6FF6E06CE62189 |
|
CONTENT
ssdeep
|
96:Tuh4f1NJKTnTQ7kr/1wSDtH3Ihtha1qEHrj2f+9ESSQ:9f1nKo7cNzYqVLj2f+KXQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ccdb33632c9d8b30 |
|
VISUAL
aHash
|
0bfc3c3a01b19301 |
|
VISUAL
dHash
|
5bd8f062a76326b7 |
|
VISUAL
wHash
|
0bfc7e3e01b1d311 |
|
VISUAL
colorHash
|
31601008000 |
|
VISUAL
cropResistant
|
808080c0d0808080,5bd8f062a76326b7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Found 1 other scan for this domain