Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D813FF726306182BDA4781D2F6193759E18AE31BCB530C85FBF182379F83D71BD29268 |
|
CONTENT
ssdeep
|
768:YaAyqrI0ahPHSSX710+K+Fy2XtV2nD5IhFpYS5e9C/4sCNU1wMZGfFKFkOC5rZY+:N5/9mx2Qj6tbCDNCO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96166df492926de4 |
|
VISUAL
aHash
|
0600302e66602001 |
|
VISUAL
dHash
|
ecfb66ecccc6c0c3 |
|
VISUAL
wHash
|
0607373e7e727071 |
|
VISUAL
colorHash
|
31603000000 |
|
VISUAL
cropResistant
|
163a2e3e3e3e3834,e0d0343afaca6b33,ecfb66ecccc6c0c3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 107 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.