Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F50374B36410643F431363C9B026775DF193C31ECE9B48A8B2ED8B970BD7DD8991992A |
|
CONTENT
ssdeep
|
768:K/ZkvhtQIP+f35cP0k82eIICx0KV3SUyzjT2SlSUyzjd1/y7KJfH0lOHFw/EnazI:K/ZkvhtQIP+f35cP0k82eII5KdSUyzjg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ad56a93b5e23a152 |
|
VISUAL
aHash
|
007272101003031b |
|
VISUAL
dHash
|
03e6c4e4b49707b3 |
|
VISUAL
wHash
|
827e76761673031b |
|
VISUAL
colorHash
|
38000006000 |
|
VISUAL
cropResistant
|
804b726971710c14,03e6c4e4b49707b3,016928174d30b10d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 822 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)