Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T181231030A801E93B41CB69C9A236671A63E68349C6130689FEF5C3F95BDFD2DDA37114 |
|
CONTENT
ssdeep
|
768:0sIx/j82+zLO+6LR+zLiQP03piX9t6Uf7rDd4N6mD:0sIxY2+zLO+6LR+zLiQP03pUtl7W/D |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
80e5f299fb89f304 |
|
VISUAL
aHash
|
ff76331f1e3c1c7c |
|
VISUAL
dHash
|
33e4c5f7f0f0f1e4 |
|
VISUAL
wHash
|
ff14151b1e1c1c7c |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
33e4c5f7f0f0f1e4,47534fc787cb630f,da9a9bd393939b99,fc7d7c7a7e3e1e3e,00e0f8b070e83161 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 39 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.