Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A453FC79FA0419A65273CAC0C5327F1932A2F34FE606C15496FC47A85FD2DFAB8319A4 |
|
CONTENT
ssdeep
|
768:fdk/TF8ou1Shh399BCLANoXHFk5dMBec0wu:fW7CnQd9BCLANoXqfMBec0wu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccc33337326cc99 |
|
VISUAL
aHash
|
1018181818181818 |
|
VISUAL
dHash
|
20b2b03030313130 |
|
VISUAL
wHash
|
3c18183c3c3c3d3c |
|
VISUAL
colorHash
|
38001002200 |
|
VISUAL
cropResistant
|
20b2b03030313130 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 27 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.