Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T123D183392140696E06278FE4B6E1EB0F618ED34CC6B39A6CB3DD11BB37C5DA0C9061A1 |
|
CONTENT
ssdeep
|
96:TJK+V7ftOTUypFCRUKkHTEoZBc8833883iKX93AYw9JYnkF/M:J7FT0cX3XisBAYw9JYi0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b087c733c63839c7 |
|
VISUAL
aHash
|
7f5fcfc3c3cfcefe |
|
VISUAL
dHash
|
c09c989696989c00 |
|
VISUAL
wHash
|
3f0f03c3c3c0ccfc |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
c09c989696989c00,0d0c06271b93c947,01100c32b2300811,5933313b33f0e265 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.