Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E3519E312088623B16C372E6B7714B1B72B6C662C6164A0012F9C24E5FD2D2ECCA736E |
|
CONTENT
ssdeep
|
24:hR/CNiHZR0jQZTFQhI0lTOjsg34oPfR9XDr5JpDReuXk8c1eW/7Y6JmH0gjh1PFL:TdZR0jUFQTOoXG9JKJ/MhHPPI46I |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d9620d37d9608a9f |
|
VISUAL
aHash
|
000000e0fcf7ffbd |
|
VISUAL
dHash
|
3164819108cc3232 |
|
VISUAL
wHash
|
000000e0fcffffbc |
|
VISUAL
colorHash
|
38000000007 |
|
VISUAL
cropResistant
|
8000806060600080,3164819108cc3232 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Victim enters credit/debit card details including CVV and expiration. Card data is captured and can be used for fraudulent transactions or sold on dark web markets.