Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15613F912458C271705A30248BB83C32FD36A10ECF76547C266E6C7AE51C8749EDB7EBA |
|
CONTENT
ssdeep
|
768:gsMy9MAk35pq4iYrBJA33f5K32WB1J3GTCHfYelnrudBcBKvyZiS7PDW8:gsMyC335IYzg3f5K32W75GTCHfYeFqcj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8067f0e001edf9e |
|
VISUAL
aHash
|
0000ffdfffffdfdf |
|
VISUAL
dHash
|
2c0f3abbb3333333 |
|
VISUAL
wHash
|
0087874f43c3c3c3 |
|
VISUAL
colorHash
|
07200030000 |
|
VISUAL
cropResistant
|
00202828282820c0,2f3bbbb333333333,0030c0c8c8000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.