Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1503362A1724105BA206747F0B2D1F394D1BCC75CDE6B9C69E39C135327C9C2EAA627B8 |
|
CONTENT
ssdeep
|
1536:ZGvNcOH/S76nuiKmm316xIxm+9qBQJyNfK7Kvzn0xTXyGR:ZEp2R |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a7bf1961e0492937 |
|
VISUAL
aHash
|
fbff83e3e7000000 |
|
VISUAL
dHash
|
926c2f470dc66071 |
|
VISUAL
wHash
|
e7ffefe3e7000000 |
|
VISUAL
colorHash
|
33200030000 |
|
VISUAL
cropResistant
|
536c2f0f674d0c0e,dffee0e8a8f0c08c,0241aaaa8aaa4000,6c0f674d8e476971,0f7262646262b20c,717171717131310f,b4b4b4b4b4b0b541 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Victim enters credit/debit card details including CVV and expiration. Card data is captured and can be used for fraudulent transactions or sold on dark web markets.