Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T174A3D77053845E39A093C794A3356B6A33AA81A19E072B0997F0C72CBBD7D8EDC275C5 |
|
CONTENT
ssdeep
|
1536:QSQZo+2OTYJosm7UMustACNnQUGoysJosm7UMustACNnQUGoyC/9CoFUhwZW6CSS:QSQZo+2OTo/9C4c |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c2c22d3d29f7929a |
|
VISUAL
aHash
|
42707e760c040000 |
|
VISUAL
dHash
|
dac4ccccc92c5113 |
|
VISUAL
wHash
|
7e7e7e7e7c060001 |
|
VISUAL
colorHash
|
300000001c0 |
|
VISUAL
cropResistant
|
2c2dd9d3adab2aaa,fcf8f8fcf1e18618,2a29a96936962256,dac4ccccc92c5113 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.