Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T168B35294B25105BB19B795D0B568FF5AE4AAF70BC21BDA0863BC80431FCFDB1E9116B0 |
|
CONTENT
ssdeep
|
1536:zEf0Cbqc4lcqecfcECcfcfvcQIc8scFhQ3JLT+xVMyMhM5MLMqMuB05D:zEf0CChQ3JLT+0B2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a0552f7da047af70 |
|
VISUAL
aHash
|
0100767ece4000fb |
|
VISUAL
dHash
|
6300cccc9c84104b |
|
VISUAL
wHash
|
81007f7eee2404ff |
|
VISUAL
colorHash
|
38200030000 |
|
VISUAL
cropResistant
|
6300cccc9c84104b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 108 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.