Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12F34F371DA4DAC7EA16363C3E72477AA3196B356DD090504E1F81237825EE8BEC3B06D |
|
CONTENT
ssdeep
|
768:YHTgTZTeTaT5TfT9TXTKTPST/zYC8eIqYZfBkEdxoY/ntUQFOtDxycdQmTbDpu1J:SMFy+dzZL2hMUoDbtKYDyFhl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c73bd21c333b9232 |
|
VISUAL
aHash
|
04206c201e7e7e7e |
|
VISUAL
dHash
|
bcc0c9c9f4f4f4d4 |
|
VISUAL
wHash
|
04307c203e7e7e7e |
|
VISUAL
colorHash
|
00006000000 |
|
VISUAL
cropResistant
|
9455554db2a54d4a,b498d97b74cd0cb4,6cef8e9494a8cce0,a9333202696978d0,b4488c9cd69c0ea7,7adad9ac2c749888,716cd4a49ac97906,bcc0c9c9f4f4f4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.