Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CE519870509A9E330292D2E5B2B35B1F37D1C656CF8B1B001AF8939D4FE6E55ED1A182 |
|
CONTENT
ssdeep
|
48:TIRCXVcPzeRKuSSbHjHFgLdEt7H0UhZGMgH1FqsSArZUwHR+sQ:T96zeBSqhgyt7zrGP1FqsMsQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e11e3dc03f780ee1 |
|
VISUAL
aHash
|
0000000466706060 |
|
VISUAL
dHash
|
78dacd5cccc8c8c8 |
|
VISUAL
wHash
|
88086c0e6e7ef868 |
|
VISUAL
colorHash
|
38c00008040 |
|
VISUAL
cropResistant
|
c9ccce8e9991a4f0,78dacd5cccc8c8c8,430b0b891967373e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Found 1 other scan for this domain