Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B6238431E0447D3B019382E5A732675FA3D58245CA130795A3FC8B6ABFC7E94DC2B698 |
|
CONTENT
ssdeep
|
768:IB44yzIGPLEwHPgScYlTLSeKsjFngDd4y6mD:IB44yzNPLEwHPgScHm7UD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec3c9383d6ad43a1 |
|
VISUAL
aHash
|
bf8f9193f1f1fbfc |
|
VISUAL
dHash
|
2b3633370723030c |
|
VISUAL
wHash
|
17838191f1f0f8fc |
|
VISUAL
colorHash
|
07001000640 |
|
VISUAL
cropResistant
|
2b3633370723030c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.