Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14A12443088C46A3B0253E6D5AF71A70BE3D1C146CD235F46AAF4878C0BDBEA5CCA5765 |
|
CONTENT
ssdeep
|
192:EaWvaXsOyPI/DQrYn3jmDZem+C3Lav9kJlQlU3b:BgrYn3jmDZVf3LavuJlQlU3b |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fce396c2a9d0e0d4 |
|
VISUAL
aHash
|
ff8080c8c0e09e9f |
|
VISUAL
dHash
|
692a323212053434 |
|
VISUAL
wHash
|
ff80c8d888e09e9f |
|
VISUAL
colorHash
|
06600010040 |
|
VISUAL
cropResistant
|
692a323212053434,3c0c1f0f073713d6,0f0703032323038f,33393918152673b3,a0038e8f1f3e63e6,30381bcb8373e363 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Pages with identical visual appearance (based on perceptual hash)