Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EDC15174958C5A3F06D782E1EB28A75F33C1C666EA4712016AFD83AC4FC1D94DFA3180 |
|
CONTENT
ssdeep
|
96:TeG+vf0nAn+5iMsskCwfz2mm1E3uT2GuGg:qG+knAn+QMNkCgz3m+uT2Gw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b333c96733998983 |
|
VISUAL
aHash
|
e7e7dfc7e7ffffff |
|
VISUAL
dHash
|
4c09199c4d040000 |
|
VISUAL
wHash
|
c0c4dcc0e7c3c3c3 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
4c09199c4d040000 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Victim connects wallet and signs malicious transactions. Attacker drains tokens across multiple blockchain networks using chain-specific draining methods (Approve, TransferFrom, Set Authority, etc.).
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.