Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E46321B1C655213B02278EE4B4706B4FB2E3C31DDE67891157FC879E6FEAC90EA05489 |
|
CONTENT
ssdeep
|
1536:HQAde9ObtohIgAHJUBpNxTaGntpoyxiGZ1zl:HCg2Vj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ba38c1c7c69e3cc1 |
|
VISUAL
aHash
|
ff838387ffbf9fff |
|
VISUAL
dHash
|
6d3b3f2f433b3813 |
|
VISUAL
wHash
|
f7818181a78f8fc3 |
|
VISUAL
colorHash
|
07400040041 |
|
VISUAL
cropResistant
|
6d3b3f2f433b3813,36968ed6d6bd3531 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 40 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.