Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T136F1C6E1ABA0A6F8C9C7CF9ABF251898354510FD56335799D26C6B4806C3FDEC84DC90 |
|
CONTENT
ssdeep
|
192:h9zz4DE9F4izbUQ4xqQ4XWf9zz4DE9F4izbUQ4xqQ4XZTbF:/RdzbJ4xr4XARdzbJ4xr4XZHF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d58f6e38cc2998d |
|
VISUAL
aHash
|
000018183effffff |
|
VISUAL
dHash
|
e81032b2f2b2c4fc |
|
VISUAL
wHash
|
000018183affffff |
|
VISUAL
colorHash
|
1a400030000 |
|
VISUAL
cropResistant
|
000080a080008000,dab1b939b1f971b9,d0c8c0f2b35b5c82,96c0c0cef4f8f8cc,685232b2f2b2c4fc,dffd99efddf3ecf9,4bdb7efebebe9ff6 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Victim enters credit/debit card details including CVV and expiration. Card data is captured and can be used for fraudulent transactions or sold on dark web markets.