Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EE4131A210125C3B4263D1D5B7FA7F1A72D2809EDBC7290092FCC3ED2BE6E44D81D566 |
|
CONTENT
ssdeep
|
24:hR/CcuDfTJ0HmapRcGAgPD0sMl/2VY0S3gC/IsmN2CV6lTupDKgP8dcKM5hNDc8D:TXCmrcG0++BqwVFYmgP8d0Znp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
da8a2ad925b7352c |
|
VISUAL
aHash
|
fdfcfcfcd8c88000 |
|
VISUAL
dHash
|
393929283019010d |
|
VISUAL
wHash
|
fdfcfcfcd8c80000 |
|
VISUAL
colorHash
|
07400010001 |
|
VISUAL
cropResistant
|
393929283018192d,78606818f8727e67,3434b430f0c0a0a0,393928381019010d,0010243232040000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
| ID | Portuguese | English | Trigger |
|---|---|---|---|
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain