Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T107835C71E101CA381F3F8BF5E56A553BD3458C0BF55218B6F6AA63AB3483F648E27016 |
|
CONTENT
ssdeep
|
1536:HYerS5nC/UvjjDkiROM96jcPbC4pWYM66yJ27T6SuZrV53JYQxKbYgNjyX71wGUj:GTM66yK6SiKbYgNWX71VU2UX0EX0bY9Z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d94b8659b658c387 |
|
VISUAL
aHash
|
f8f8f8d8c8c8f8ff |
|
VISUAL
dHash
|
819110101011b148 |
|
VISUAL
wHash
|
f8f8f8888888c8ff |
|
VISUAL
colorHash
|
17400008040 |
|
VISUAL
cropResistant
|
819110101011b148,209081b0b232b408,2e672da53331590f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 540 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.