Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T192B39734604214FB416B2ECAB7A31F091156D11DCA3BDA91A7FCE3EA2BF3DD5646420E |
|
CONTENT
ssdeep
|
1536:fMZ8gn2e9o9s8sm9XV2sPLofSzG8jhudR9W/00tKrJKzuM/naqy0vSW8QB9:/zG2wRnQz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6c93926c62996d |
|
VISUAL
aHash
|
fffbd1f1b1ffffff |
|
VISUAL
dHash
|
3b33372727160f0e |
|
VISUAL
wHash
|
89f1818191f7c3db |
|
VISUAL
colorHash
|
07400018000 |
|
VISUAL
cropResistant
|
3b33372727160f0e,1c3c3c1b5b5d2503,f5f5e1f54b68152f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.