Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F263C9B28158153A038763E4EF51BB5DE3C35305DAD74BE2D6E5CBAA6989DC2E80703C |
|
CONTENT
ssdeep
|
1536:oYhYGuCbZII1ge21TrUTCXqvivdVy4VymOhcMdVl8yFXOu83VmvyTw/IuBv6iXIH:jhYGuCbZII1ge2YviVRR3VmvycBSiiKc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0cf4f314d324f31 |
|
VISUAL
aHash
|
00ffcfc7c7c7c700 |
|
VISUAL
dHash
|
9e100f1f1f1f1c0f |
|
VISUAL
wHash
|
00dfc7c7c7c7c700 |
|
VISUAL
colorHash
|
0e002018000 |
|
VISUAL
cropResistant
|
3e1e0f1f1d1f1c0f,02028c9e92902080,d4d4938f9c939679,4901555515570029 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.