Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10754656A1202CDD39C4DDE9659E1C91424B7E4DF73B65248E8D6A27FF8CCC808A48BD3 |
|
CONTENT
ssdeep
|
6144:AUasBc0zndqmEgGKrU0qwV9j4jHHosVGRBZ2v6Z88+5XXbGfeFxc1YWWWW2WEbVN:AUasBc0zndqmEgGKrU0qwV9j4jHHosVi |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b6b05d496a5a456d |
|
VISUAL
aHash
|
070f0f0703008080 |
|
VISUAL
dHash
|
2f9e9ead4f9a3226 |
|
VISUAL
wHash
|
070fcf0f07ef8883 |
|
VISUAL
colorHash
|
38201000440 |
|
VISUAL
cropResistant
|
f3616131a1cfaf7f,a0812d0d8388e6a6,2f9e9ead4f9a3226 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 289 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.