Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F3B2B71163991D13B35778E8B492EF6F372A46A2A359C67C2BE12061D2CCCF259E07CD |
|
CONTENT
ssdeep
|
384:+2tlKHsle/t1+dL54KpGKnQioR14rLHmq:+2tlKHWksLnQioR14rLGq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
937284f1ce6ae8c5 |
|
VISUAL
aHash
|
ff040000efcf001f |
|
VISUAL
dHash
|
98181959599b7a66 |
|
VISUAL
wHash
|
ff0c0000ffcf063f |
|
VISUAL
colorHash
|
03200000180 |
|
VISUAL
cropResistant
|
d858181969599b9b,f4defeccc8d18387,478c183831e18144,9a1c39393b393129,0040d08011155858,d818b9595b9b7a66,494604193236393c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.