Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11E31AB203841883F29B385E6A4B17F0E348AE759C70A58C01BE946DB7FC2D78AF560E4 |
|
CONTENT
ssdeep
|
24:hFrN+8reZzVE00XdAUihY1DvDbcYfTpizz+3iN+UDj14a:dEVVQyhYJRTpn34+UvD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c9b0355d45675d98 |
|
VISUAL
aHash
|
1bffd3e0f838001a |
|
VISUAL
dHash
|
aab7ab8ab0e0f2f2 |
|
VISUAL
wHash
|
3fffc3e0f838001a |
|
VISUAL
colorHash
|
0a402018000 |
|
VISUAL
cropResistant
|
f8dcfab818dafcf8,c78ac7eac2c7e5cd,dddadbb9e8487236,2454945a525556aa,e8c84c7c6c60411f,e0e0e0e0e0e0e0e0,aab7ab8ab0e0f2f2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1006 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.