Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T157D1B6B20201093B42A38BE5B6F4F795D1BB825CC76BC945F3DD42DB27D6CA095B6228 |
|
CONTENT
ssdeep
|
96:j2Qe46YPpbo222eBW/ICmQBrPekeshrCYS3qkSMH+EncSTR:j2QzLpbyBSPeG0dSM9VN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc333366cccc99 |
|
VISUAL
aHash
|
1818181818181818 |
|
VISUAL
dHash
|
3030b2b230303030 |
|
VISUAL
wHash
|
3c3c3c3c18181818 |
|
VISUAL
colorHash
|
38400018400 |
|
VISUAL
cropResistant
|
0000802727000401,4836165913320014,3030b2b230303030 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)