Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1038264B38C43F01F965B84C9E5305B2DA9939E2EDA234D84A3FE4B93F7C4D82C601585 |
|
CONTENT
ssdeep
|
192:6T91hB5fVCMt877TCiwBkzBVX4G+rUL56aG75YxV9zce6BsWpfMSygy:2uIuzXFRAwYe6BfBRy7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c0be483e6b3e51d1 |
|
VISUAL
aHash
|
00fffee7e600707c |
|
VISUAL
dHash
|
b1a28c4ccc8eaad8 |
|
VISUAL
wHash
|
00f37ee76640747c |
|
VISUAL
colorHash
|
06440008200 |
|
VISUAL
cropResistant
|
f4b4b4b4b4b4b4b4,b5a28c4ccc8ea8d8,c6c591b3a296caf8,b4b123b9b2b9c9a9,24505091d06c5340,371f998381331ebc,c4c490b2a6c6c8f0,5bd2b333b2303233,c0c0c1922d693529,4f61b1a3c70db1f9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 30 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.