Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17753EDB0124015AE0BD2F9D095A2BE03A1B6C9E7E21F6DCE61F8954D1EC2FE5C9C17E4 |
|
CONTENT
ssdeep
|
1536:6YQ7RbLRd2/aJGmXwEgxuNZ8xcej+pBOW0UWOYALoaKPC7Rs8VmDT:6YyR3Rd2/aJGmXwioALV2B |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e9b7129a4d9813c7 |
|
VISUAL
aHash
|
ffc7e3d1f1d1f100 |
|
VISUAL
dHash
|
2b2f0b33331727d3 |
|
VISUAL
wHash
|
ffc3e3d1f1c1c100 |
|
VISUAL
colorHash
|
07e00000000 |
|
VISUAL
cropResistant
|
2b2f0b33331727d3,4a08cacbc9484a4a,82808e9e96e000a0,a200b28c8eb20080,8280868c8c9280aa,a200e09e968e8086,49d471c8cccccc71,ca928e0e4f0f0706,0a48004040401068 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.