Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1246363B15113B97BA2A7E2E251795B1F72F2C286EB471B11A7F843AC1BCEC40DD13462 |
|
CONTENT
ssdeep
|
1536:A44fnYwjpd4N2bkbPaBH1Cu4tMuzu0vMVHsw/CGUgxqf3krmjBhEyS5vBDKSwxJ1:y1Wu66v6LAUHIY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c9817a7a2765707 |
|
VISUAL
aHash
|
061818dbdb181800 |
|
VISUAL
dHash
|
d4b332232bb2320c |
|
VISUAL
wHash
|
4f9918ffff181a00 |
|
VISUAL
colorHash
|
30400038000 |
|
VISUAL
cropResistant
|
9a496d2d17cceccc,e0f064d2d8ecb4d8,f8f0d8b5e4d8b6cc,d4b332232bb2320c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 41 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer checks balances of popular ERC-20 tokens (USDT, USDC, DAI, etc.) and only proceeds if total value exceeds minimum threshold.