Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1530512B750A82D39874783C79250F71ED5A7E25DCB40CE83A9E1EA4DAED0EB1E5400F9 |
|
CONTENT
ssdeep
|
6144:epcabmBH9/DcO+rv9ddEceMwR2Lzp0XyZy9Vl/5qiw5Tu9A19z04yzCcoU:BIOexEceMwR2Lz2XyZy9Vl/5qiG51cpv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99c9662699367699 |
|
VISUAL
aHash
|
e0f89898981b0307 |
|
VISUAL
dHash
|
85aa3b3332362e1e |
|
VISUAL
wHash
|
e0f8d8999b0f070f |
|
VISUAL
colorHash
|
06006400000 |
|
VISUAL
cropResistant
|
94b1b192a48899a9,38d88ecfe799cea8,85aa3b3332362e1e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 771 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.