Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15D52D6275189313A43D301E2BB762785A2FD99C9E5B36E0263FECA9C47D7C489C2F941 |
|
CONTENT
ssdeep
|
384:aw1NkjY55YYjbDKUcw9yv8qIYuAzL+X7XgSuD2qz+:aw1NkM5hDKUcw9yv8+u77XK2Q+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3e73c389bc81ce1 |
|
VISUAL
aHash
|
c060707e6c306020 |
|
VISUAL
dHash
|
9ccec6c8c8c8c6c0 |
|
VISUAL
wHash
|
e0f0727f6e7c7020 |
|
VISUAL
colorHash
|
3801e000000 |
|
VISUAL
cropResistant
|
9ccec6c8c8c8c6c0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.