Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T136C33F7175036936216B52DBE2B7370E31E1E389DF4302E5A6F8C36C9FE9CA4B962540 |
|
CONTENT
ssdeep
|
1536:ovjDv8af8oP7zj0RWi/1HehvNFPxPUipiEAoKQ+Qo6f7DClpxuwKIkjcfskri7oy:ovjpidY1P7peFQVf/U4ONnL0w/w |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e3344d12671e6d9a |
|
VISUAL
aHash
|
0000ffe7effffff1 |
|
VISUAL
dHash
|
ccdcd4cccc88a8c3 |
|
VISUAL
wHash
|
000066e6e6fefee1 |
|
VISUAL
colorHash
|
0ee00010000 |
|
VISUAL
cropResistant
|
d4d4ccccc8a8a8c3,642400d4d40bc8c8,460c1d59cdcec74f,24252525a567858d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 146 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.