Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B852961C152137772683C3727A30EBED73DB1A99CA1B4E4523F4820F9FAAC81CE15969 |
|
CONTENT
ssdeep
|
96:nQdTidQ0z/FJlDRvlmpQ6Xb13IfzvIMPq3JIIuKyzKL/K7ifCRTKWDugviuz+B6k:QZGA55sA0DCuHm4WiKmWk0nCBIAVm3P |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b84739c6643cc739 |
|
VISUAL
aHash
|
00000000ffffcfcf |
|
VISUAL
dHash
|
9631e2868e101e1e |
|
VISUAL
wHash
|
00000072ffffcfcf |
|
VISUAL
colorHash
|
03000000180 |
|
VISUAL
cropResistant
|
e6e68ea6101e1e9e,80b280935bc08080,b60c30f2daa6c68e,1919981811111313 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Pages with identical visual appearance (based on perceptual hash)