Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17573C8A025621ABDB20B5F9877F2E388311B7195DBCDE5D4A2D902D482CBEF8CC5F581 |
|
CONTENT
ssdeep
|
1536:qAYFqgtqS/8Y7luAWg3YcIAKahulg3YgYhg+an0+0ObYq0ue5TIq8AWM5TrttAWT:qAYFq0qS/8Y7luAWg3YcIAKahulg3Ygo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd8d27617127a18f |
|
VISUAL
aHash
|
433cff18585a0000 |
|
VISUAL
dHash
|
8e61617192964910 |
|
VISUAL
wHash
|
433cfffdda7a0000 |
|
VISUAL
colorHash
|
38006000040 |
|
VISUAL
cropResistant
|
8e61617192964910 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 90286 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.