Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DBF1A5F250C0693306974AC6A634BF5EBBD081A4D6D2231806FEC358DFD6E6EE917D42 |
|
CONTENT
ssdeep
|
96:TzGWmtMByrx6GqtnNIROVuKJ0Imjzrpzk9zbQacZ/SkWY1qWXLh1t3obyWBKZQ5J:HmtTNq9NIsXJ0J8wiY1xLVY2WmrV22hK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d3699a96e47161b1 |
|
VISUAL
aHash
|
3c3c28203c3c3c3c |
|
VISUAL
dHash
|
c871d0c4c4c8cccc |
|
VISUAL
wHash
|
7c3c38303c7c3c3e |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
c871d0c4c4c8cccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.