Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14D12970150D4317541C786676E329F99FBB481604FA2231A97BEC34CFEC68D8DE6B68B |
|
CONTENT
ssdeep
|
192:MR1t4stdvztSiLQ0Rhs2XSf7PlFP6kuMGnKA6IEoL:20ovzFLQQlO7PlLTspX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
898cac83867c7c77 |
|
VISUAL
aHash
|
3f3f003c7e3c0000 |
|
VISUAL
dHash
|
f3ff33f0ccc0d006 |
|
VISUAL
wHash
|
7f7f007e7e7e0000 |
|
VISUAL
colorHash
|
30600000030 |
|
VISUAL
cropResistant
|
f3ff33f0ccc0d006 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Pages with identical visual appearance (based on perceptual hash)