Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14F613F719088693B96C383D9DA54A7DF32C6828FDA1707015BF993689FC4DC3EE21075 |
|
CONTENT
ssdeep
|
48:T6sfBGrVOOaVQP1ZIbXGrVOOagz5ZyW0ckz+zeGekslKm8cpVA9ZGS5T:T6sTOa6dZIbROagzryW0cjKsssYpsz5T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d7cc6c623388c973 |
|
VISUAL
aHash
|
fcf8f8f8e0f0c0c0 |
|
VISUAL
dHash
|
000030200c000000 |
|
VISUAL
wHash
|
f8f8f8f8e0f8c0c0 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
000030200c000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.