Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1902540B3884A622E829DD3C466317F1FF39383C6DDE487DAA4B647D19849B70CD0466B |
|
CONTENT
ssdeep
|
6144:HTk3MbjbSch5eMwF2lipMXyZyAVv/Jqiw5Su9r1fB04yzjt3C:w3Much5eMwF2liOXyZyAVv/JqiGf1opy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d88ce3b7885a7259 |
|
VISUAL
aHash
|
ffff98d8dfc280f8 |
|
VISUAL
dHash
|
6db13133320e0d31 |
|
VISUAL
wHash
|
bfff9898988280f8 |
|
VISUAL
colorHash
|
06200180000 |
|
VISUAL
cropResistant
|
6db13133320e0d31,43673131696060c9,00000c9e9e064001,5151a6b2a8c8863b,1b5b9b9a964745a7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 733 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.