Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10AB2E9F69141013B0253D3C65309776AA3A200DEFE824E83F9F5435D979BE66D9322EE |
|
CONTENT
ssdeep
|
384:8aEbI6LnT+87vcw0vk00jVJQogHxn6UzIo+xZbDXMC+jd1z2z3:8a2BLnTj7F0vkTVJYHx6Ue8NFi3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c364e476333361e |
|
VISUAL
aHash
|
00ff8eeffffffffb |
|
VISUAL
dHash
|
cc2234dce4d0f2f2 |
|
VISUAL
wHash
|
009f1a4e3a787e7a |
|
VISUAL
colorHash
|
07007000200 |
|
VISUAL
cropResistant
|
cc3234dce4d0f2f2,034c2cdcd4cc2c02 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.