Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T120A44361F380D429164781763BBFE984413AAE54EF06671BBC77CC219A856BD1B33B2C |
|
CONTENT
ssdeep
|
1536:n7sIxpXoybz7bz1tbzbbzObzWbzFbzhbzjbz1Ybzbbz5bzpbzFbzebzWbz1zbzbi:7lGyL3T7P |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a36c7c30ed92ed11 |
|
VISUAL
aHash
|
8083377f7b270e80 |
|
VISUAL
dHash
|
1b0fcdc1c3cd4c45 |
|
VISUAL
wHash
|
8003377f7f270f81 |
|
VISUAL
colorHash
|
300020000c0 |
|
VISUAL
cropResistant
|
2173436a262553d7,f1d8cca6e2ecc6b2,1b0fcdc1c3cd4c45 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6753 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.