Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10432753F93255C17127790C5A2EA3205186A1247DB4A4B51ABBE33EF2FE5C75EC32286 |
|
CONTENT
ssdeep
|
192:Q4/B9dIYB9l999mbRUjIazaitcrML/9999mVBR9999HiM/999Pm9999RK9999y5Y:Q4BkaEa2itcrML4B1iMpobY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8326f8f80703f8fa |
|
VISUAL
aHash
|
e7e7673f3fffefef |
|
VISUAL
dHash
|
cb0dcdf0c41c9c1c |
|
VISUAL
wHash
|
e1e161003fc7c7c7 |
|
VISUAL
colorHash
|
07000030001 |
|
VISUAL
cropResistant
|
cb0dcdf0c41c9c1c,b6a475ad4ecdd6d4 |
Victim enters banking credentials including account numbers and security questions. Attacker gains full access to victim's banking services.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.