Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T158D132B280812417523FA8C4F96E7F1971A7C34CD96B1264D3B94BB48FCAF85ED26215 |
|
CONTENT
ssdeep
|
96:TGCQOD0Qe6W+17Klcdid98MWIX9QMWwE818VY4XA4rek8Vuf4qqBTjKzjo202m:aCQOo/TvlcIs5M74rbffqB8MB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c9bc66c38c2f6998 |
|
VISUAL
aHash
|
fefed91878682020 |
|
VISUAL
dHash
|
e0983371d1d1c9c4 |
|
VISUAL
wHash
|
fefed83878782820 |
|
VISUAL
colorHash
|
0ee00000000 |
|
VISUAL
cropResistant
|
c0e0b0a84c8e9cbc,b6b2f0c2e1c2b2b1,e1d0bad2ea8c3ebf,3f1b8886c0e9f7f6,e0983371d1d1c9c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 7520 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.