Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T110B209312128353F635782E4F135776AA19EC29EC62B849463FC53E1AFC3CD1CEAA245 |
|
CONTENT
ssdeep
|
384:6vubxTL2xInPqCLra/kOTZQdMslF4TZTZrM0sTzl/u/Lr3fPg/DkfU:6vubZL2xoqCLrawMQHl/u/Lr3fPQDkfU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd5cb163259859cb |
|
VISUAL
aHash
|
000018100080ffff |
|
VISUAL
dHash
|
127171b34046002a |
|
VISUAL
wHash
|
0090bc1830f1ffff |
|
VISUAL
colorHash
|
3a007000000 |
|
VISUAL
cropResistant
|
7470d35b3151646d,030000000000002b,12227171b2634341,2b298a8a2a2a8300 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.