Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F413DC70B44328172137D6C0F4A6AF44319BEB32C6644A98B3E925B6BFCDCF46932764 |
|
CONTENT
ssdeep
|
768:wDWcUS6TV83ayh4aYhoaGhsL3Z0uGBnesBne0BnekBneMBnesBneO4HapeT5YIBM:cWcUSLayh4aYhoaGhsL3Z0BnesBne0B7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b00fce0e3ac24ebe |
|
VISUAL
aHash
|
00ffff000300ffff |
|
VISUAL
dHash
|
6552819e1e85a088 |
|
VISUAL
wHash
|
00bfff000200ffff |
|
VISUAL
colorHash
|
0600a000240 |
|
VISUAL
cropResistant
|
6552819e1e85a088,26b510101970e1e1,b324d892a2e20e07,2bcbe0f0d0f0b092 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 39 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.