Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T193B2852112042E3F5527C6E8F6A5B336A2AAC249D63FC919E2FD02B267C7C45D5372D8 |
|
CONTENT
ssdeep
|
384:DyO4jJUjzOGOwO3svYlYhnPqYK/3UFsYhUFsYwoUMB7SUCWpDM9tNX1YHYKT:4J2OWYlYMYQUaYhUaYuLUHY/NlYHYG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a400dd9b2cbc9f39 |
|
VISUAL
aHash
|
0000000000ffffff |
|
VISUAL
dHash
|
bec6ce8687793322 |
|
VISUAL
wHash
|
0202020343ffffff |
|
VISUAL
colorHash
|
020000001c0 |
|
VISUAL
cropResistant
|
f7ededcdcdedffff,c6ceae86ff323322,5a96d65625929213,b9bdc2df6f654767,1bc480a6a680c42b,bee7c6ceee86867f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.