Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DAA4A375B6B05A7B908E77C5FA001BD4EA9B63ABCAD28FC061ED96841746C84C773C1C |
|
CONTENT
ssdeep
|
3072:iopP3k1rroqYUHP9kPr5okAjgY/SbMLNW/SbMLTd/SbMLx/SbML3hv/SbMLH/Sbn:tpP3k1rroqhHP9kPr5okAk+5H |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
82a2a48d754fc72f |
|
VISUAL
aHash
|
f7ff0100003c18e6 |
|
VISUAL
dHash
|
ac95e52931f0718c |
|
VISUAL
wHash
|
ffff5100003c18ef |
|
VISUAL
colorHash
|
31206000000 |
|
VISUAL
cropResistant
|
96c7a60f3e94b490,0f0f27a78382b6b2,89e38e9ccc0f1368,ac95e52931f0718c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 148 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.