Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CE3394325045643B132753C9F023771EE1A3930ECA8718A9F3FC8B934BE3D99991986B |
|
CONTENT
ssdeep
|
1536:46DA62FvhtQIk65350PcQ2kwfdrj81quTa2dM7Kb0VOU3j9gOsr5Zdl49h2SURbo:zuvXmZTa2dD6JVFeWyolfwHD1g4cXKTo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a152af2d52afa552 |
|
VISUAL
aHash
|
000040404003033f |
|
VISUAL
dHash
|
440c8c8c8c8747cf |
|
VISUAL
wHash
|
f70666766007037f |
|
VISUAL
colorHash
|
38200031000 |
|
VISUAL
cropResistant
|
68ede7dbd5d966ea,440c8c8c8c8747cf,01d978270d30710d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 813 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)