Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11A02DEE05055BE3B0263E0C6E24A5B5331E1C26ACF9E260146BE52FB5BF7C60E91E507 |
|
CONTENT
ssdeep
|
192:dVeiyLgtHhuNqPuoDj22jVxtUOAsII3qlxaa:dVluc26PjVxtU5sII3qlF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dcf4a51a61b62f0a |
|
VISUAL
aHash
|
ffffbfd618180422 |
|
VISUAL
dHash
|
32a26ea6b1716dc6 |
|
VISUAL
wHash
|
fffebf5218181022 |
|
VISUAL
colorHash
|
00e00010000 |
|
VISUAL
cropResistant
|
e6c4c0813c3c0c87,b1a9c989b9abaea5,232263606383c7cf,829a9a86b28e8eb2,e9e2e4e1e3c3e3c1,3898d87c3c38385c,41c080e0e4e4e87a,7dddbcb0b0f03080,01e0214933060dfb,32a26ea6b1716dc6,434ba90525934e5c,41444242009fc038 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.