Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18DA26621760430261A739AC8F5B27F2AB9B1F32BC16D9BA466BC49960FD3D70F403579 |
|
CONTENT
ssdeep
|
384:mlwYlrc8rtYWmbyt53QsnR3zwHGXHKGpByGFiOGTHp39hxA+F:mlWWj3QsR32GXHKGpByGFiOGTJmo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4a56b1e6b4a4a69 |
|
VISUAL
aHash
|
0206660646060600 |
|
VISUAL
dHash
|
26cc8c8c8ccc8c83 |
|
VISUAL
wHash
|
8766766ee6760660 |
|
VISUAL
colorHash
|
31201018040 |
|
VISUAL
cropResistant
|
eec4c6f2929cc2fc,26cc8c8c8ccc8c83 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)