Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E0E2943122081A3E66A783F5F6B1B36A12D9E286D617436993FD437D4BC6C91DE332D0 |
|
CONTENT
ssdeep
|
384:MBq+bTRrxEVO+oaN5/0H0DFEYE22GuRLF1NS9Qd9a894H9G29wx9Kg9Ib9cR69qI:STRrxEVO+oM2PFpe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c38cc37c316c39cd |
|
VISUAL
aHash
|
3c3c3c180000706c |
|
VISUAL
dHash
|
f0e070707218c8c8 |
|
VISUAL
wHash
|
7e3e3e3c08007e6e |
|
VISUAL
colorHash
|
38001c00000 |
|
VISUAL
cropResistant
|
f0e070707218c8c8 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Victim enters credit/debit card details including CVV and expiration. Card data is captured and can be used for fraudulent transactions or sold on dark web markets.