Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F2E285712111097E45D383B0F1716F7ED1EA93C8DA63959DB2ECC3526F8ACA9CD8A350 |
|
CONTENT
ssdeep
|
768:B9q7s6Y7XbPCDOdQTUG4p/k5r0a+9LxlMRd4ca2w:BcVw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f1a9db295329528b |
|
VISUAL
aHash
|
f9ffe7c3ff81c3fc |
|
VISUAL
dHash
|
1b344c8e64070754 |
|
VISUAL
wHash
|
c9bfc3c3a38181f8 |
|
VISUAL
colorHash
|
070000001c8 |
|
VISUAL
cropResistant
|
1b344c8e64070754 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.