Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F474A471B22A483751374FC5B3A4AB0972D7E34DC7134848B6FC439897CEEC6B852A99 |
|
CONTENT
ssdeep
|
3072:mO5WogogjxIpSZmWLC/VVIy90TrBToqvto4DX6MMEx2pow5Mo4/AtKu0F4coh1cQ:mO5iDJu+KtX01GxUzN4LQ2PFxp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a804bf947ac2cfc5 |
|
VISUAL
aHash
|
ff000000ffffffc1 |
|
VISUAL
dHash
|
6dd7d099b2004f1b |
|
VISUAL
wHash
|
bf000000dfffff81 |
|
VISUAL
colorHash
|
06c00048000 |
|
VISUAL
cropResistant
|
63796dd7b7d7d590,cb8bf1e26efc3c29,fbf9e6e2e5e1c4c4,111850921a521798,b096050b0c4d1b1b,cfb7d7d0d0c189b0,0181a52f696d4e46,0f080d0d84466646,b2eb45cdedcdad1f,9c0c2f576ae9899a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 269 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)