Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FBB35CB43684A17525F343E3609B6E02B67C531BC90F9C70B224F89B66BDC6AD463F85 |
|
CONTENT
ssdeep
|
3072:l/bCrdETqLBDqa/4xVREfeY0nFlMIlV8XjUMAL98n0dH++v:+z458n0dH++v |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4b8319b9a9b8b23 |
|
VISUAL
aHash
|
ffc3e7ffffffc3c3 |
|
VISUAL
dHash
|
3b8e8e2424700e8e |
|
VISUAL
wHash
|
8dc3c3cf7e2e00c3 |
|
VISUAL
colorHash
|
070060000c0 |
|
VISUAL
cropResistant
|
3b8e8e2424700e8e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 262 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.