Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BB035C72318018AB1A63C7987AD1B52CE0C1F19BEE13C594C2DE519B5AC6EF3CC726D5 |
|
CONTENT
ssdeep
|
768:Xx4wwB9lRCpml2iqdtKPrd5yc8AYdYPY6Yu9lwIPDeHla4TWnyIhYFhKWy7:B4wwPU1doP9lZP17 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b1b1b1b2b2b2b2b2 |
|
VISUAL
aHash
|
ff00000000000000 |
|
VISUAL
dHash
|
0800000000000000 |
|
VISUAL
wHash
|
ffb5000000000000 |
|
VISUAL
colorHash
|
38000000e00 |
|
VISUAL
cropResistant
|
0800000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 803 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.