Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T110F21161314001B70DE3A9D9B661BF0AB1B1F32ACB4FE062AE9C40D55FC3C6D79A1A75 |
|
CONTENT
ssdeep
|
768:7goSK8nIcQDMs0y05rw+s05rq+s0mK7tT477M7T7EBiyL6TvLSTOM9BPMD7TP:7gRV9KBiyL6Tvk0j |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b43649eb6934b496 |
|
VISUAL
aHash
|
0046f642ffff0000 |
|
VISUAL
dHash
|
6a8484b44b0f88b2 |
|
VISUAL
wHash
|
83e6f6c600ff605a |
|
VISUAL
colorHash
|
38e00000000 |
|
VISUAL
cropResistant
|
63e3e0d96868f43c,0f0f0f0f0b0f0f0f,6a6394c48cb44384,0d308accba9a66b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.