Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14F824FF2D6C422EEB417DF73E925AB66B28B347F1530CD508A5C4F5EE2652D0835A883 |
|
CONTENT
ssdeep
|
384:t97bw2Pz27lGtim1pk7r2PPaL6/Pfk9QSWW:ts7lAiX7U3/67 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92686cd345fc926b |
|
VISUAL
aHash
|
00000e7e6e0e0000 |
|
VISUAL
dHash
|
918998dcd8180c52 |
|
VISUAL
wHash
|
404d4f7e6eee8e02 |
|
VISUAL
colorHash
|
30400040202 |
|
VISUAL
cropResistant
|
050b0b0a0a16067c,e8683d55e2ece8f0,918998dcd8180c52 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 27 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.