Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E3A13F15928C882B1B1392D8E7206F6EC9C2F3A6CF5B5A4197F4975D92C9D33DC630E1 |
|
CONTENT
ssdeep
|
48:+mV2QHCYV3ELUWBrsBswBzPaQbqoFXBx3pEkxWIxkHx97x3vqOs6iD/Ue5HCx4d3:+nYVQBQzyvfcceZ5W7u/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9d9c36279296393c |
|
VISUAL
aHash
|
8018183c1c180000 |
|
VISUAL
dHash
|
2e70b070f0d65430 |
|
VISUAL
wHash
|
9f3c1c3e3e1a381c |
|
VISUAL
colorHash
|
38002640000 |
|
VISUAL
cropResistant
|
2e70b070f0d65430 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 241 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.