Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B66285B2A0447D3794A3C3D9EF31973E93C282C9D9870A59ABFD874D4AE6D50EC1C50A |
|
CONTENT
ssdeep
|
192:XuII/D/wHCS+XHsWkte+lK015XDnQbhg1q3LT8zaIzzRJ40:XuII/EinlkvlPzQ9gU7TAzd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8e1c6cb449c61be |
|
VISUAL
aHash
|
ffff8f9b89c99f00 |
|
VISUAL
dHash
|
25183b33331b3429 |
|
VISUAL
wHash
|
ffff8f8181818f00 |
|
VISUAL
colorHash
|
07e00000000 |
|
VISUAL
cropResistant
|
2d183b33331b3030,008037c8c8174000 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.