Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1347577F622001A78083777C8A920F96DC31F636DEF6BCA6D61B5CA11F2D5AE5440DE78 |
|
CONTENT
ssdeep
|
12288:nxGhcltUrkXhw/Bsz8WbRkWyi61Pxe4bdk48WbRkWyi61Pxe4bd/Q1VbsPIsIsq0:SsIsQsIsqsisQsLsosY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c0c007177e7a5b3d |
|
VISUAL
aHash
|
387efff5ff7e0000 |
|
VISUAL
dHash
|
e0c4808586d0c8d4 |
|
VISUAL
wHash
|
087efef1ff7c0000 |
|
VISUAL
colorHash
|
01000210010 |
|
VISUAL
cropResistant
|
e0c6818586d8c8d4,f4eac2e0e4ccd0d3,377d7bc38b073cfd,64f1f1c988094a98,c08589c04581410d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.