Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T105E2C72512041B3CA543C3E8F7A5B778926CD299D31A851CF2FD027A26D7C99E93B3D8 |
|
CONTENT
ssdeep
|
384:Wv9YEmTYQGYr1ABejsn2NxYfWoFQFx213c1BCq2NjaNcFK:WVYXTYvYuBeIUYtmwOXkaNcFK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9111ea9a9aed4dd2 |
|
VISUAL
aHash
|
1d0002020607ffff |
|
VISUAL
dHash
|
69dcd2d2dc7b0c4e |
|
VISUAL
wHash
|
ff0202020607ffff |
|
VISUAL
colorHash
|
13001000180 |
|
VISUAL
cropResistant
|
004141696951017d,ff3e27272b1f3e7e,3a00210c0c0c0442,ffdcded2d2dedcff |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Victim enters credit/debit card details including CVV and expiration. Card data is captured and can be used for fraudulent transactions or sold on dark web markets.