Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F6328562E69526B782D300DEA630AF8AF774C2016F562B4C90BEC35C6BC3CD5D93A553 |
|
CONTENT
ssdeep
|
192:MbhMflZKmgbNrBFyKkS/vEtc/+bHI2W5PT:s9mgbVL/vEtc/+82W5PT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc9397667939246c |
|
VISUAL
aHash
|
3c3c081818001818 |
|
VISUAL
dHash
|
60693232b2263030 |
|
VISUAL
wHash
|
3a3e3cfcd8103c3c |
|
VISUAL
colorHash
|
310060000c0 |
|
VISUAL
cropResistant
|
60693232b2263030 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.