Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T193F25CB2318018AB1663C39876D1B62CE1D5F19BEF17C584D2CE519B5ECADA3CC722D4 |
|
CONTENT
ssdeep
|
768:Xx4wwB+lRCpml2iqdtKPrd5yc8AYdYPY6Yc9lwaPDeHla4TWnyIhYFhKWy7:B4wJPU1doz9lfP17 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b2faa22a88b8eab |
|
VISUAL
aHash
|
01033f3e06061c1c |
|
VISUAL
dHash
|
5bb3f2febcecf8b0 |
|
VISUAL
wHash
|
03033f3f071e3e1e |
|
VISUAL
colorHash
|
07000000000 |
|
VISUAL
cropResistant
|
6464d7d3c3d99932,5bb3f2febcecf8b0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1871 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.