Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C483E87651002373815343D279BA2F0FA3B98184E7131D68AAFE835C2BD2D549A77BBD |
|
CONTENT
ssdeep
|
1536:r44Y9tncunwVk7dIZCOvs5ywJ4dZ9bEtyLGN6AF91BXnjNVhBpQkV532ENps/1cv:Iqdkjk+D3EVSN3/WorHQA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc3731e69c338c36 |
|
VISUAL
aHash
|
0610383cf8f84058 |
|
VISUAL
dHash
|
84e1f0e0e0a09cb0 |
|
VISUAL
wHash
|
063078fcfcf860f8 |
|
VISUAL
colorHash
|
38000188000 |
|
VISUAL
cropResistant
|
fefffa2f2fdafffe,84e1f0e0e0a09cb0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.