Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T106A25621760430261A739AC8F5727F2AB9B2E32BC1799BA466BC49960FD3D70F403579 |
|
CONTENT
ssdeep
|
384:mJZdmwYlrc8rtYWmbyt83QsnR3zwHGXHKGpByGFiOGTHp39hxA+F:mYWWG3QsR32GXHKGpByGFiOGTJmo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4a56b1e6b4a4a69 |
|
VISUAL
aHash
|
0206660646060600 |
|
VISUAL
dHash
|
26cc8c8c8ccc8c83 |
|
VISUAL
wHash
|
8766766ee6760660 |
|
VISUAL
colorHash
|
31201018040 |
|
VISUAL
cropResistant
|
eec4c6f2929cc2fc,26cc8c8c8ccc8c83 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.
Pages with identical visual appearance (based on perceptual hash)