Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13C3100A7815AA93B0B53C1D175BDBBAF26C1C249E7C7070117FD839D2ACAD94EC550C2 |
|
CONTENT
ssdeep
|
24:hR/OpsjDfqwHMMizCmutszNPgl7TYKNZ+IfblbPDoiGqA35GTp/JPULbLLI5e:TGp4/sMizCmJNcTZNZPbRHG95GTsA5e |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
903e2e2e2b9aab99 |
|
VISUAL
aHash
|
00007e7e7e7e7e7e |
|
VISUAL
dHash
|
dc8c9cbaba96ace8 |
|
VISUAL
wHash
|
00007e7e7e7e7e0c |
|
VISUAL
colorHash
|
070010001c0 |
|
VISUAL
cropResistant
|
80985858d8c0d080,8c9c90b8ba96ecc8,8c9c90bab296a8e0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
| ID | Português | Inglês | Trigger |
|---|---|---|---|