Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BC64E7FC733088D1896A03FE9B67ED98207AD4EA97005504D32C5BB4A4A49FF6C739D6 |
|
CONTENT
ssdeep
|
3072:J1qc5zc25x05lj6DsnsCd5aXk05lj6DsnsCd5aXC6:J1V9x6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
95625cd6a5c4adac |
|
VISUAL
aHash
|
100040263f3e3e1e |
|
VISUAL
dHash
|
a60182c6f4e8f0f0 |
|
VISUAL
wHash
|
d00071663f7e3e1e |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
a60182c6f4e8f0f0,2d2d020000000000,f6fcb99aa8e196bc,797e7b3b3b393d8d,ecffdfcccdb7e6c4,79793979793b3f3f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 801 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.