Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D53324339877A13F025DB1C8E160BB4865476387C7C647FAF9E1C26E1EE99588C136AC |
|
CONTENT
ssdeep
|
1536:hKxd95YVe6wOp26922yI7qTeLslFwcTBVRuuG6pHyYBYxL5ignaynI4hZFHUy/6B:aWJhV4X |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
848404faf8f87bf1 |
|
VISUAL
aHash
|
ff0023ffffffff00 |
|
VISUAL
dHash
|
71e4c6e0c2510d98 |
|
VISUAL
wHash
|
ff0000ffff00ff00 |
|
VISUAL
colorHash
|
07240006000 |
|
VISUAL
cropResistant
|
39e4c6b9f680514c,fd797174f4f4f474,1400001018081814,0000999888385898 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.