Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FC9433B8131C3E2CA42B87E4F761B769126DA150FA5AD0A8D6BC517117CBC89F83B9C4 |
|
CONTENT
ssdeep
|
1536:JzTps8v18v18v18v18vo8v18v18v18v1svL8v18v18v18v1svm8v18v18v18v1B8:JzAUXCjjUXCjr1z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
867987f0cadca01f |
|
VISUAL
aHash
|
ff02020000413f3f |
|
VISUAL
dHash
|
228eb6a5adad766f |
|
VISUAL
wHash
|
ff00174105473f3f |
|
VISUAL
colorHash
|
02000430000 |
|
VISUAL
cropResistant
|
a28eb6a5adad766f,a2902b27252788a4,31b6b635b1b1b68e,195aca8ab9b94a46,ba8cea8ba92a2aaa,a2baa29aaaa2aaa2,0000000000000000,d3179bda92929331,15170b1b1b1b1511,33b13325ed41050c,4a5bdd4368285ad8,6d6d9b898dbb7b5b,65c55501d0f0c209 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)