Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T112735479E181043B063741CAB066671A38E296C9DD872FD1A3FCE3A92FDFD61BD12845 |
|
CONTENT
ssdeep
|
768:pqVijwi51JPBrFmMR31yU3JR3IT9Prhk4JHSNo:UDi51JPwI41Si |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3d33c2c4c3c3ad3 |
|
VISUAL
aHash
|
007c6c7c7c000000 |
|
VISUAL
dHash
|
16c9c9c1c4594948 |
|
VISUAL
wHash
|
80fcfefd7e3c0020 |
|
VISUAL
colorHash
|
30202008000 |
|
VISUAL
cropResistant
|
8403e0e080603183,8008907c6ca00882,16c9c9c1c4594948 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.