Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12403FBB74191123B011393C6B3593BA3D3A150EBEF814EC1E4F54358A7CFE66A9326E9 |
|
CONTENT
ssdeep
|
384:913XjaGTwcjka0v+f8oKHTGiPNYywit1HJvzTa47GZ0RVgyTiNbscHV7QjoTNLSi:94V+kbzGi6IZaiPR6pR17Fa7hW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc92cb3c24c3d3e1 |
|
VISUAL
aHash
|
ff9fcf838383fffb |
|
VISUAL
dHash
|
333c981e3616f236 |
|
VISUAL
wHash
|
df0646020303dbdb |
|
VISUAL
colorHash
|
07200010000 |
|
VISUAL
cropResistant
|
333c981e3616f236,4dccae8e8a8e4d4d,5356b4115a95e2b4,534694115a956230,5652526c6cca9232,6dc73d67efee6e52,b7d7e66675e9d555 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.