Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DC63E731D1A45437453746C5B8946FAAA2CB834EEE530211BABC47E84BF7C63EC2B578 |
|
CONTENT
ssdeep
|
1536:XiVLWdAkt7xCv1JGahvKvNvevQvM2v9vhvjvov2vTv5vov/vtvpvcvTvvv6dBQuN:SV+AktSEahCFWI02FZ7w+bRg3FhkL3y/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a43bd6530b94367 |
|
VISUAL
aHash
|
003c0c0404ffdfdf |
|
VISUAL
dHash
|
28f8e9b9a8bc3e3b |
|
VISUAL
wHash
|
003c0c0c0cffdfdf |
|
VISUAL
colorHash
|
0b007000040 |
|
VISUAL
cropResistant
|
dada4c5c5c5cdcd4,8ce8393a3f3b3b3b,f1e8e46cbcf0f8d8,28a8f8e999a8ac8c,6c78183c3c6c6ccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 80 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.