Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CDB31D1AE1E21A3287AB8EF0B07B673D7B398C5D9FD11C305C9673BB1642E82571958C |
|
CONTENT
ssdeep
|
3072:9HqqZjispgNmzUmBE+GnIWnIjiD99jifRjaiWZR/IkkChznFHD/9n3qRnrnyXw0I:9HqqZjispgNmzUuE+GnIWnIjiD99jifl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b372cc815ccc99b9 |
|
VISUAL
aHash
|
efe7c7c4476fffff |
|
VISUAL
dHash
|
8c0f8f099d99ee36 |
|
VISUAL
wHash
|
67c7c1c0454f2fc3 |
|
VISUAL
colorHash
|
06200048040 |
|
VISUAL
cropResistant
|
8c0f8f099d99ee36,c749835dc0c51711,0000203232300800,0d070d0781d14d47 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Pages with identical visual appearance (based on perceptual hash)