Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1421548EFA780EDAFB077045D7059FBC8C307960BE5984DAA33C5494B26DB8724A412ED |
|
CONTENT
ssdeep
|
3072:V2v2aBEj9EOgv+gM4I23csK6fHxL1oNW0X7gv+Hse7IZ5/g2vtmM5lJw/3eVSSID:Vm8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9cea0278738d86f3 |
|
VISUAL
aHash
|
05957fdbca183a24 |
|
VISUAL
dHash
|
29adb33212b4ea6c |
|
VISUAL
wHash
|
05d57fdbca1c1a24 |
|
VISUAL
colorHash
|
19000003040 |
|
VISUAL
cropResistant
|
d8d8e368ccecf868,060c193668d1a7c1,8f85e1e1b098cc06,c160ecacb0d8d874,e260713163d19c26,0d2c2c1e9e9a6830,f8e43d1cae365e6a,27accc499832e286,29adb33212b4ea6c,981c2e3673434379 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 33 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.