Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14933103571512AFB41C7D7F2B6616B6EA2E9C78DCA57CA89A2F8C3895FC7C048D01318 |
|
CONTENT
ssdeep
|
768:w9BRsW455r+RWjheDxrPhWL/ZImVbIdKgDd4+6mD:5c6he5WumVbIdK7wD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a0629d3cbd93a7c4 |
|
VISUAL
aHash
|
0761716143131c1b |
|
VISUAL
dHash
|
be83cb8b87e73073 |
|
VISUAL
wHash
|
0f61716563131f1f |
|
VISUAL
colorHash
|
30000000e40 |
|
VISUAL
cropResistant
|
2d095d3a25a5b234,be83cb8b87e73073 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.