Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T176633070D29D587B4083E1C2F619BF0AB6E540BDEF93075642F45B6E2BE7D20CEA6124 |
|
CONTENT
ssdeep
|
1536:exb8kAK1Kq/uUDpzZWdRcfbXLz4xV4MQ4Qn44w4H+4Zk4uD4qm47v4NWS4Z2VTR4:exLD4z4F4C4z4e424S4N4T4Z4IVltC1f |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
97333638cd876c8c |
|
VISUAL
aHash
|
04043e3e18003e3e |
|
VISUAL
dHash
|
4948c4d070d0ece4 |
|
VISUAL
wHash
|
052c7e7e18087e7e |
|
VISUAL
colorHash
|
38040208040 |
|
VISUAL
cropResistant
|
4948c4d070d0ece4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 76 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.