Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19F74D8F0A318A2BC581BC3D9B9296C24731F20EB7AC5CCB8466C8ED05593DD9DE468D7 |
|
CONTENT
ssdeep
|
3072:b25iSQwfCe88mv8wD8x3AgNC6AqXqnd/GoY11wwr3rkNxhmrFmRPmywmvTmdKm6L:b255tCe88mv8wUNC/qXqndlfXvCS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9cdd2ad4a30f6a70 |
|
VISUAL
aHash
|
99de583bc6d00001 |
|
VISUAL
dHash
|
7130b2569c343401 |
|
VISUAL
wHash
|
bdfeda3bd6940001 |
|
VISUAL
colorHash
|
38000008080 |
|
VISUAL
cropResistant
|
7130b2569c343401 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 141 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.