Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11102B53030409D3F162785A5B4E1F31B925AD30DC9ABE97AF2D802B727E6D90C9775A1 |
|
CONTENT
ssdeep
|
96:smNdvbCnKyY4t78y2Wk60/uP5LR88xHwNweOcY0AY/jcfkNIGO:sm7aYe0b21RRHwNw6Y0AY4fsIX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4e44b39b4e03c3d |
|
VISUAL
aHash
|
0200167767060000 |
|
VISUAL
dHash
|
aea1accccc7cd158 |
|
VISUAL
wHash
|
c35477f77f0f0800 |
|
VISUAL
colorHash
|
301c0002000 |
|
VISUAL
cropResistant
|
6b69970d060fcd8e,6b6b90959595946b,aea1accccc7cd158 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 13 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.