Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12642803261148B6751C383C8ABFA6B0B33A0C285FAA317404BE5879D9DD7DB7DC342A4 |
|
CONTENT
ssdeep
|
96:uZ9ZbnZPab888/aW4DZ+Stb/jY+eo4hAryAes9mBYYQgWLDmrUTmvybzMojyIT61:+bnvUoSBjlevudl9ndbzM5I4Isw8IGmy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
85d970e6329959e6 |
|
VISUAL
aHash
|
00363b3f377fff00 |
|
VISUAL
dHash
|
c8c4f2dae4e6e6e7 |
|
VISUAL
wHash
|
00303b3f377f7f00 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
c8c4f2dae4e6e6e6,c6c7c3c3c7c6c7c6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.