Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A872C512E1A0A536732BC7D8EE31BA5021B7F3EFD150C0E490DF862879A6DFAA715C54 |
|
CONTENT
ssdeep
|
384:pVnZ3qmPLaq4ahTmrMMTjnxwU0Alb8zUb:rn1qsLaq4anMTjLrb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9313ec6c69ed6c12 |
|
VISUAL
aHash
|
000c0c0c0cfeffff |
|
VISUAL
dHash
|
2318dcd8dc280033 |
|
VISUAL
wHash
|
000c0c0c0cffffff |
|
VISUAL
colorHash
|
03002c00000 |
|
VISUAL
cropResistant
|
080800001818189c,b08e96a6a2968ca2,808ccce68888c850,0015952280884810,01c4c09696c0d4c0,0000403870683333,00100c7171080000,1818dcdc58dc9818 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.