Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1247230A0F5A5AB37429343C9736AA37A32E4D246CBCA169117FD83AC0BD2D91FC17057 |
|
CONTENT
ssdeep
|
192:2tUk5opGKUkBvxAvHHHHjLMcdFGjkVYjk66q1Ujkgg9jkWwwjk/dZtGK+:2akpZk+MTkEkPo6kX1kUk/dZtGd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed6d9292076d493c |
|
VISUAL
aHash
|
f9db91d393ffffff |
|
VISUAL
dHash
|
2b3232163638036c |
|
VISUAL
wHash
|
998b81c382ffc30f |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
2b3232163638036c,e4723d0e87c7c1d0,996c7636030349c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 72424 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.