Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T140C2BAB0B115B83706A7A2D267A7671A72EE920CC922034267FDD7BE0FE5DD8ED13105 |
|
CONTENT
ssdeep
|
384:0s+offviDyUAD3vdLHWCm1L3FwGbd43mUIN:0u3iDyRXMrd43mD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c46eb1393ab4ca65 |
|
VISUAL
aHash
|
00303010107e7e7e |
|
VISUAL
dHash
|
ccc5e5f471f0cccc |
|
VISUAL
wHash
|
00707c3c187e7e7e |
|
VISUAL
colorHash
|
31401400001 |
|
VISUAL
cropResistant
|
5d32954962a2325c,b4a4a4b2f2929696,5d49a1cbdb971717,ccc5e5f471f0cccc,37ccc8d8d8cc4c4d,abc4c4e4e45a4a49 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)