Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T186034070D0615A3B81436AD1A3706B1E7BC29308DB630766AFF88B5E6FCFD11CD265A4 |
|
CONTENT
ssdeep
|
768:heDrXtkoWEmH8zZHl3+v0heqtwGrH+K0PId4Q6mD:heD7moWEmH8zZHl3+v0h9twHjGD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ecb8913d9a2991ba |
|
VISUAL
aHash
|
dff0f0f0f0f0f0f0 |
|
VISUAL
dHash
|
36e626272566a781 |
|
VISUAL
wHash
|
d1f0f0f0f0f0f0f0 |
|
VISUAL
colorHash
|
06402008000 |
|
VISUAL
cropResistant
|
36e626272566a781,9c3b299c6ccccc95,5c726222eaf9f9b0,9f9c998181838387,cddd959396d8dcdc,b4a5f5455d109c87 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.