Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17DF21131D85E603B0133B5C0E8A3DF456CE2520EC7534964E2FE925D6BDEEB5B923826 |
|
CONTENT
ssdeep
|
768:JCgzV3CaekkKTwOfXrFmZhV/hK9TPqT/zuF1aphNHw2sP2VhqTF18Ehao78zC2hr:JDzJMGXrFmQl+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b255c6c8a9ad3276 |
|
VISUAL
aHash
|
ffff00000000ffff |
|
VISUAL
dHash
|
0054bc3b3dbd6d49 |
|
VISUAL
wHash
|
ffff00000000ffff |
|
VISUAL
colorHash
|
13000000380 |
|
VISUAL
cropResistant
|
0084001c0c3c3a3b,3535406d6d714d6d,3c3c3a3b3f3d3d35,4323938d8fce6464 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 356 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.