Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17FA138625141B87300ABD2D167A6AB6BB7E6824DCD035B0217FE83DE5EFFC45ED22106 |
|
CONTENT
ssdeep
|
96:Tal2lexQHlmlblK5cQr37H/nld9ndrMqAbNLSgk:tVmFH/k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
86563b5ccc696b4c |
|
VISUAL
aHash
|
007e247e7e0000ff |
|
VISUAL
dHash
|
97eccca4a4c8c0df |
|
VISUAL
wHash
|
007e747c7e3400ff |
|
VISUAL
colorHash
|
30201408000 |
|
VISUAL
cropResistant
|
c8b93a5a32a6e464,3b3b79b17d63bb59,fffcfef6fefcffff,97eccca4a4c8c0df |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.