Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T103D31CA453642AFEB70383E4F620B2B8B217B175DA1FCA1893FC175467DAD5E8426DC0 |
|
CONTENT
ssdeep
|
1536:NdwCnsTT/ln+2vyQVKyQV6MSkdwCnsTL/ln42wyQVzyQV6T4:id+sjd4J |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c953e34b894bb2b2 |
|
VISUAL
aHash
|
7c200018180000ff |
|
VISUAL
dHash
|
49c4613371514911 |
|
VISUAL
wHash
|
fffe9818180081ff |
|
VISUAL
colorHash
|
3a007000000 |
|
VISUAL
cropResistant
|
49c4613371514911,0304a49c9ca48483,5914b45919a5dedb,2a1a9a6c41697a9a,94d5e5a7a6595199,47b0b48ccccc92b4,f08230131396a0f0,c8c4cc33b270d041 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1090 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.