Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D7B223317588363B0107B1C6EB206F5E32E241ADFFAB272112F597AF2BD3E018D26119 |
|
CONTENT
ssdeep
|
384:Gw2BiD3PBWt+VCF3PH1s3hRXVvThfAm6FZf8B2VI3DxWifi+H606O3OZWxHvu:7CiD3PBo+VCF3PH1s3hRXVrhfAjFphIu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
edec12b812cb3b92 |
|
VISUAL
aHash
|
fff3e3f3c3c3c300 |
|
VISUAL
dHash
|
26268202971796f0 |
|
VISUAL
wHash
|
fbd3c3f1c3c1c300 |
|
VISUAL
colorHash
|
07002000380 |
|
VISUAL
cropResistant
|
26268222969716f0,0323777161667113,6c70a2acb0b16070,a2a2d4e871b34d29 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.