Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13F52543563481A7DA69787E8F6B1733861AED38DD32B845CF3BC01B25783C94C9672A4 |
|
CONTENT
ssdeep
|
192:Yu2upfZZPGsbwoK9a6oBtvOZLOWZ697y6ZxYz1Pk+cirhQlky5QfZt:mupfZZFwPE57GX5dFxa5QfZt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed6d9292966d6858 |
|
VISUAL
aHash
|
fd8b81b3bfffff8b |
|
VISUAL
dHash
|
49323262650d0f2b |
|
VISUAL
wHash
|
bd8b80b2b8e7ab81 |
|
VISUAL
colorHash
|
07000200050 |
|
VISUAL
cropResistant
|
49323262650d0f2b,196c76360b0341c9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 205 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.