Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D0B1B5313108692A45538B927EA1FB7EB1F2E208C62A155AD2FC53ED0BC4DD4CD9B506 |
|
CONTENT
ssdeep
|
96:TkgtuabJF6KdvUjnXxVd04v+AGn+veAeAhDPtREx:IBAhdcjnXd04c+veFezk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a72636191d37331d |
|
VISUAL
aHash
|
00ffe7dbfbe7e7e7 |
|
VISUAL
dHash
|
4c0e4c16324c4c0c |
|
VISUAL
wHash
|
00c3c3c3dbc3c3e3 |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
4c0e4d16324c4c0c,000d0f0f0d100800,044b156d49014d03,656d2e725eac6b27 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6929 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.