Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E2242B25040AA3A51E3D3D27A71337EE3C6D2CCD54A1B091AED8B0E4AD6F21ED19847 |
|
CONTENT
ssdeep
|
192:K/ofLp2VII2I11AOEBy8GCEvo6GNE/noGyEaGSeW65N67Wj:yULcIIp1AvB1GCEvo6GNE/noGyEaGS1s |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
86473939474e7879 |
|
VISUAL
aHash
|
00ff1f7f7f9fdfff |
|
VISUAL
dHash
|
d6bfefcccc3d3fdf |
|
VISUAL
wHash
|
0001037f3f1f1f3f |
|
VISUAL
colorHash
|
00000038000 |
|
VISUAL
cropResistant
|
ffbfedcccc3dbfdf,4524d4d0d42c45df |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.