Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17CA1FAB1092C5433738FDBE8F6A9650B9B61C78EC3695E0151F843AE96C3D94CCD1954 |
|
CONTENT
ssdeep
|
96:/HKMKs3wylLU/8jSVjX6N+nzl+4zWGb/MZ7:/es3wyS/8eJX6OzNb/MZ7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a6f619a3e31c58b2 |
|
VISUAL
aHash
|
bffff7ffe7000000 |
|
VISUAL
dHash
|
7ccc8cc5cdc6f248 |
|
VISUAL
wHash
|
0ffff7f7e7000000 |
|
VISUAL
colorHash
|
01002640000 |
|
VISUAL
cropResistant
|
5d6ccc8ca5c7cdcf,e1c91004043ceef6,b5f8d292c676bade,82a29c333392aa9a,1101010303010101,cca4c7cdcef0fe68 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1327 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer checks balances of popular ERC-20 tokens (USDT, USDC, DAI, etc.) and only proceeds if total value exceeds minimum threshold.