Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15D3329B4A284A3B9024BC3F5B731F63AB257A6DDCE23C94A83F496C36695C8DCD415D0 |
|
CONTENT
ssdeep
|
768:mbOvanBohhsPatpy1K5xRd/dUJflRsmMmFoqULB9Z1d/MJfp9:mod/G5Fzw9nd/C |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91b16ece9991664e |
|
VISUAL
aHash
|
ff0000ffff000000 |
|
VISUAL
dHash
|
d0015894f1acacaa |
|
VISUAL
wHash
|
ff00c0ffff6e0020 |
|
VISUAL
colorHash
|
30000007000 |
|
VISUAL
cropResistant
|
8001c2d2d2c20180,939393aab2360626,367666c6c696972b,c0909090901020c2,d09393a4a29694c8,d08b8396162626c4,d0969384a2260626,a3a3b3b2b2321a1a,0000000000000000,1000d49469aca8aa |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1764 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
| ID | Portuguese | English | Trigger |
|---|---|---|---|