Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B3426290FB089C96363342B6F1C1BC09E484B71AC725B8E0F38A467B94C9B394E257CD |
|
CONTENT
ssdeep
|
384:lqEB0UAkmW4c47ghq9ifGwL09xhIqCad2w/3Y7q3K3f8:j0UAkmW4c47ghq9i+wL09xhIPy3Y+3K0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
edb992864d4b612d |
|
VISUAL
aHash
|
ffdfc9d993f32400 |
|
VISUAL
dHash
|
433a1333325249c0 |
|
VISUAL
wHash
|
ffcf89d193fb0000 |
|
VISUAL
colorHash
|
07e00000000 |
|
VISUAL
cropResistant
|
433a1333325249c0,39306ae8d472e9aa,83072163e3c3371e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1220 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)