Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T158B2FFA0A5509A3B4313F1D4C9A5AF3BB381D209C95B9943A3FD83FB5ED6C10DD0662B |
|
CONTENT
ssdeep
|
384:Zq4DJah5ydNmbu80FvuXPyKgEBM7yOr1Gbi6Cn5sk:dlmaHhRGG6Cn5sk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
871c34f6157394cb |
|
VISUAL
aHash
|
021838383c7e2032 |
|
VISUAL
dHash
|
d4f2f2e2e0cc43c6 |
|
VISUAL
wHash
|
0a383a3e3e7fa832 |
|
VISUAL
colorHash
|
39000e00200 |
|
VISUAL
cropResistant
|
d4f2f2e2e0cc43c6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 922 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.