Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BC416516F218384A479312F1BEA18299AB7E449166220B0C42F9D06DB6E5BC7CE550BF |
|
CONTENT
ssdeep
|
48:Tr8JOw9mqQS9h5YSkpvLBWSL7KtP5Gy0YU/05UZW5tK8s:Tr8AwciYBVk9l0mW0a |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b867c26632c7c53c |
|
VISUAL
aHash
|
e7dffb8383fbdfdf |
|
VISUAL
dHash
|
0e22623a3ac23c38 |
|
VISUAL
wHash
|
0076b89883fb9c8e |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
0e22623a3ac23c38 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.