Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T160F29538324099BF41D793F1F6A1AFBAB2D5E345C957C75DE2FA82982BC2C91CD44214 |
|
CONTENT
ssdeep
|
384:eFcwwfa3HcfZWmzjxDcrGAutgfqNhDuLH+c1RcWnlv:xVfZWWjxwbrfl+wt1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96966d694b92b4b4 |
|
VISUAL
aHash
|
0066666404200020 |
|
VISUAL
dHash
|
96cccccdad496ccc |
|
VISUAL
wHash
|
67767674043c0076 |
|
VISUAL
colorHash
|
38000000188 |
|
VISUAL
cropResistant
|
9ac2e5e1e2c2a2a2,96cccccdad496ccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 273 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
| ID | Portuguese | English | Trigger |
|---|---|---|---|