Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BE13A772C8D811371A2356C477D4B75AD1C2838FEF164682C6ED468D87C5DE2BEA3829 |
|
CONTENT
ssdeep
|
768:VZLZAeeVszAeeXhDAeebOvAeeJHEgAeeFfm4AeezgmAeevivAeeUGdZK6pPVoptd:7LqeeVsUeeXhkeebOIeeZE3eeFfceez/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b492c3cdcd32329b |
|
VISUAL
aHash
|
ffff87c3fb83c3fb |
|
VISUAL
dHash
|
2b2e2d2e322f0e26 |
|
VISUAL
wHash
|
cfc787838b8383c3 |
|
VISUAL
colorHash
|
060010000c0 |
|
VISUAL
cropResistant
|
2b2e2d2e322f0e26,e6e1e46ca9f2f4fa,96d3ececb0e86e6e,96889088c8c9cbcf,c3c1ccccccecb2f6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1025 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.