Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11BD55DD27203B826469F91F5C4BF642EA377180D850894C0FAD5C96D376EF8911E2BFA |
|
CONTENT
ssdeep
|
49152:gN4fdSeKSU4tclOUewColnr9ZE7m7R6jitw9il5grZb:J9r |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d296b686842c6dd7 |
|
VISUAL
aHash
|
fffeac007e000000 |
|
VISUAL
dHash
|
dc5c5cb1d4d47010 |
|
VISUAL
wHash
|
ffffeed47e000000 |
|
VISUAL
colorHash
|
30200008180 |
|
VISUAL
cropResistant
|
08304c4c4c080000,08304c4c4c080000,08304c4c4c300000,dc5c5cb1d4d47010 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1248 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)