Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12F044A3D674C543602A771F1EDEB0B4E7AB24225D7034891A2EECAC129D4DE4A27DDF8 |
|
CONTENT
ssdeep
|
3072:US8oVQSnvC4imK+VNVyQ/Z2G1vEV5v2d8fY5ElDvPhaCeZN:x84QSvCjv+cQ/sG1vQ5vL+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e7e71c1c611c1c73 |
|
VISUAL
aHash
|
00ffe0f0ff0000ff |
|
VISUAL
dHash
|
644848c008800000 |
|
VISUAL
wHash
|
00ffe8f8ecff0040 |
|
VISUAL
colorHash
|
07000030001 |
|
VISUAL
cropResistant
|
64c04848c00a08b0,0000000000000000,3434b03474744448,8040404040000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 96 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)