Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17C221F71B8847A3B519B83EA7B31C75AB3D2C601C7870A64A6F9C38D9FA7C05C963305 |
|
CONTENT
ssdeep
|
96:Te47D4pCUcrnT328s28128S28L28w2ykBxfDBvUBG1B3AYhfiYE3towfj2hGNo32:lH4FcbZfPfvIlj2hSo3wuJE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c88e6436733eec0e |
|
VISUAL
aHash
|
8378380c8c7300c0 |
|
VISUAL
dHash
|
07f3f33808e6f68a |
|
VISUAL
wHash
|
e378389ece7f0260 |
|
VISUAL
colorHash
|
39c00000001 |
|
VISUAL
cropResistant
|
07f3f33808e6f68a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Pages with identical visual appearance (based on perceptual hash)