Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EC63F77194104BBF81C383D5FF369B6A3346A195EB634A8082FDC76C9ECBC88DE26554 |
|
CONTENT
ssdeep
|
1536:GdKUEccxp7bWekMdsER7FUBoVa8666Y/0wJiRw:GOccxp7qeZvN6jY/0wcm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fc2d5c81c389d696 |
|
VISUAL
aHash
|
818183c1e7fffffe |
|
VISUAL
dHash
|
0b37370b0f0c3234 |
|
VISUAL
wHash
|
80818181e3ffdfdc |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
0b37370b0f0c3234,4141010000014141 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 54 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.