Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CA342D30B400EC3341DB66D869B65A1E62E9C310D9234689EEF5D3F91BE7C6CDE27291 |
|
CONTENT
ssdeep
|
1536:qisIxCCeEOyv2RHpZnmNaM7J3iyjZ7O/0OMTIczdpZnkNaJZ7O/0OMTIczdpZnkj:p4ySpZnO74vi3pZn6i3pZn6i3pZne |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e3caa8d8aec3abc0 |
|
VISUAL
aHash
|
ff00600000004001 |
|
VISUAL
dHash
|
6bc4c8c040c9c8d3 |
|
VISUAL
wHash
|
ff60606000606063 |
|
VISUAL
colorHash
|
300000001c0 |
|
VISUAL
cropResistant
|
34836b6b6b6b8304,20c8c84030c9c0d3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 210 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.