Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E6933360FA524833007386D092F6E7263182F38AEB435DD193F897795FEAE75BD06188 |
|
CONTENT
ssdeep
|
1536:AJkpciYDfWjjjjj7eeeeeFjjjjweeeeFjjjTeeeFjj0eeFjVieFN4FNjLH5HgcVb:rjjjjjUjjjjijjj+jjojVDoTleXccBMh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
953e62c02bb52df2 |
|
VISUAL
aHash
|
024002027effff00 |
|
VISUAL
dHash
|
ceae72feea8a8c96 |
|
VISUAL
wHash
|
4252121a7effff00 |
|
VISUAL
colorHash
|
02001000180 |
|
VISUAL
cropResistant
|
3109090909030e09,3c2c9e9ecddada0c,2a7272aa4cda5cc5,71cc9ea7979bc3dc,b2cd8c8ccccc8c11,ceae72feea8a8c96,5d7b714d693b3b3a,3e7f57cfee7a11c3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 81 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.