Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12A13C619664427290E5301CBF6265BAFB3BC41ACF2B703C974EFC265569481FAA37F41 |
|
CONTENT
ssdeep
|
768:JVpB4Q424y4j4YT4sEMuILnxI8EYm7Kh7Hz48pXNGpXDeC:pB4Q424y4j4g4sRn28btT4GGJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c2cbc934343fc2d6 |
|
VISUAL
aHash
|
78787c0076607078 |
|
VISUAL
dHash
|
d2d3e9e0e485c1c1 |
|
VISUAL
wHash
|
78787c1876707c78 |
|
VISUAL
colorHash
|
30007000000 |
|
VISUAL
cropResistant
|
d2d3e9e0e485c1c1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.