Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D284E8ED8360417C6117CA9FEB32AA54235FE07CF502EA948EAD57E37583EC1E407A19 |
|
CONTENT
ssdeep
|
3072:8U+zckpVwif+wZuZ6ZdZnUxTE+wyeuY9e2tHtZBuJU:R+zckpzC2P+RYBBP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dfb520cacba521ca |
|
VISUAL
aHash
|
828482bebc808000 |
|
VISUAL
dHash
|
4624446071605440 |
|
VISUAL
wHash
|
fe86a6bebcbc8080 |
|
VISUAL
colorHash
|
38200418000 |
|
VISUAL
cropResistant
|
4624446071605440 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 959 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.