Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19F5419BCB16452B7E437C7E8E5227E14309772EFEB858250C2F907685FD6CBA68094B4 |
|
CONTENT
ssdeep
|
6144:rh++SNWavvcHwCJJ6nh6n46ntTJJ6XCI6NA16Z354VjJJ60zi6JJ6uFu6eau6MN/:rhFT7z7x7x+Za7z7x7xT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8432c26bc97b1de5 |
|
VISUAL
aHash
|
08460e4a0300787e |
|
VISUAL
dHash
|
5bacac9aa62bc1d4 |
|
VISUAL
wHash
|
0d764e4e43017d7e |
|
VISUAL
colorHash
|
30003000040 |
|
VISUAL
cropResistant
|
2090c8e4f0f2fef8,270719204524234a,a6a7a63278707838,5bacac9aa62bc1d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 328 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.