Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17B239231A0456A3B029382D1B7744B8FB3D18289CB63079567FDC36E5FDBC92ED16298 |
|
CONTENT
ssdeep
|
768:LfD46mcuBjI0TFsdi8FsdtTFsd6L3feUeUeUeUeUe/e8e6e6e0eZert73ZvUSOYR:P4XBjIIFsBFsnFsofeUeUeUeUeUe/e8L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c112ed1a65e740ef |
|
VISUAL
aHash
|
000c0000000cfff3 |
|
VISUAL
dHash
|
d8f8cad8d8b00b83 |
|
VISUAL
wHash
|
003e3e2e0c08fffb |
|
VISUAL
colorHash
|
0e2010001c0 |
|
VISUAL
cropResistant
|
08000b0b0303838b,dcf8b8cadad8d0b8,0000041a32b232cc,0010081032b232cc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 62 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.