Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T184E2636D1116247F6237C9E576207749E1A7A31CCF3B9D08B7F8422A7BDAC428EC2539 |
|
CONTENT
ssdeep
|
768:P9+C5oFe/13odaW72A0RvG0dAIpmp2pDpap3papIpypYpapvpWpIXHLL0lLL0EXP:P3J+AFAawg1UZUaMKUxAbb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ac19c1c34b6bd369 |
|
VISUAL
aHash
|
f99b8f9797f7f1f1 |
|
VISUAL
dHash
|
6b36372727052703 |
|
VISUAL
wHash
|
b98b838191f1f1f1 |
|
VISUAL
colorHash
|
070080001c0 |
|
VISUAL
cropResistant
|
6b36372727052703,0551a6d4d423d445,01100cb2b2320c20 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1086 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)