Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14D23A5352240093E65638AF9F2A1B32DE17ED39CC237895CF3EE01B527D2C54AA27794 |
|
CONTENT
ssdeep
|
768:PPFOhyyTVfCf1fZfSYBrfzgo+mi0dKBVYdMPK4sXXYpS8Xfv17cqWiYeu2FuTewP:w1VfCf1fZfRrfzg/mi0dKB9rIo0o3JlE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a19ace319acd9b64 |
|
VISUAL
aHash
|
ffffe7ffc3c3c3e7 |
|
VISUAL
dHash
|
680e8e0c9696968e |
|
VISUAL
wHash
|
ff00c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
0e000000180 |
|
VISUAL
cropResistant
|
680e8e0c9696968e,61f0d0b2b0b09092 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 262 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer scans for high-value tokens (USDT, USDC, SOL, memecoins) and prioritizes draining based on USD value. Low-value tokens are ignored to optimize transaction costs.