Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D6E134612165EA3641F791D1B6D21B7B21E1428CEA820251E2FEC3F90BF4CADFD73492 |
|
CONTENT
ssdeep
|
96:TBWIxs8sJ0nW4NBsVc89zrmRQNgBIW8RxJJGtIPRdiqZ5FVfiE:1tvnWmMc89zr0n8xJOAfN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e287329a6dce3293 |
|
VISUAL
aHash
|
ffe7e7f8f8dcfcc0 |
|
VISUAL
dHash
|
71cd4d72d1996196 |
|
VISUAL
wHash
|
bfe36038385cfcc0 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
71cd4d72d1996196,00102cb2b2300c00 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.