Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FC43F9F57966F257597251EA00EF2807337CA52B780C8CB1E211EFC9A5B8068607FF99 |
|
CONTENT
ssdeep
|
768:+Y5MoTXr5h3nMQDvqDuaqGjwPMbhFkY6iQFbGBcgILCufgxT4ZtMPgF47Yffz:5MwdhZbqDNqGSMbXmbGWCufSTutygSuz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ccc33b3d90cd476 |
|
VISUAL
aHash
|
00001818ffff0000 |
|
VISUAL
dHash
|
910910b0f0940110 |
|
VISUAL
wHash
|
ff0018ff7eff0000 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
910910b0f0940110 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 55648 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.