Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EF12C723E2862735038B4278B617A3DCB7218099DB192681F9AE434D1590DEFC27FBD6 |
|
CONTENT
ssdeep
|
192:V5uFIQ1hos2M6qGkm0UGfqFnXrRf85TWM4llj:V5rQ1+7UeXGfqhXZ85Td4bj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
966969716d960d96 |
|
VISUAL
aHash
|
2004363626062626 |
|
VISUAL
dHash
|
d2ccececccccccec |
|
VISUAL
wHash
|
78043e3e263e3e36 |
|
VISUAL
colorHash
|
3000b040000 |
|
VISUAL
cropResistant
|
0020755140301000,f7afdbdbe3f3ffff,febfe7e5973f7dee,b67f4fb333637dbe,b48233331b5a4282,c2a15959e64649a2,febf6d6ddadf75be,a6db59a9b9737f9e,80185a5b59616080,d2ccececccccccec |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.