Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A792A52A7540D27E06631B91BAC1FDE4A752B249C1598279C0FBC3BD05F1EE2EC3A856 |
|
CONTENT
ssdeep
|
192:XsPG43GUeSqT74qJy9rqORFZpSXpQ75WqoMXX7doBbSujXTYI4h+ST0FO:XsKSqfC5PW0Hcdjj4M5O |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8c8c9e96f0da5acc |
|
VISUAL
aHash
|
1f1f1949637f7f00 |
|
VISUAL
dHash
|
f476b393c6ccccd0 |
|
VISUAL
wHash
|
1f1b1951637f7e00 |
|
VISUAL
colorHash
|
01e00000001 |
|
VISUAL
cropResistant
|
9092ac8c8c8b83c6,f06e6e6e6e66aeec,aca6a3ababb2a2c2,23232d0cacc8cac4,f476b393c6ccccd0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 281 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
| ID | Portuguese | English | Trigger |
|---|---|---|---|