Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C91251348888A53B0693E1D5EB70AB0FE2D1D14ACD232F4696F4874C0FDAEA1CCA4795 |
|
CONTENT
ssdeep
|
192:saR5stCIwFyhGdIciujmDZem+C3Lav9kJlsKU3b:5dIciujmDZVf3LavuJlsKU3b |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fce396c2a9d0e0d4 |
|
VISUAL
aHash
|
ff8080c8c0e09e9f |
|
VISUAL
dHash
|
692a323212053434 |
|
VISUAL
wHash
|
ff80c8d888e09e9f |
|
VISUAL
colorHash
|
06600010040 |
|
VISUAL
cropResistant
|
692a323212053434,3c0c1f0f073713d6,0f0703032323038f,3339391815266313,a0038e8f1f3e63e6,30381bcb8373e363 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Pages with identical visual appearance (based on perceptual hash)