Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FEC209EAA3C921F8E00AD3E4D7A3A1BA771725FA7F52D504C7E85E589602C2DC845CC7 |
|
CONTENT
ssdeep
|
384:Kcuvsb5RWJ6RZV5YEG53M3eIGYQF41M7hWLmXslzRjIMC0Xycuvsb5RWJ6RZV5YI:CvJ6J5A5ctGjF41M7oiXstSvJ6J5A5K |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
929b948da53d7296 |
|
VISUAL
aHash
|
1e3e4c4c4c440606 |
|
VISUAL
dHash
|
bcdcc9dcdc8d9ccc |
|
VISUAL
wHash
|
1e7e4c4e6e4c0e4e |
|
VISUAL
colorHash
|
07001048040 |
|
VISUAL
cropResistant
|
30eaf434b0b1b9f1,8a33b2b2c46971b2,71dc9ebadadabaf4,bcdcc9dcdc8d9ccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 251692 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.