Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T166133071C091603B03B383C0A675676E73D3824ECB230B5463F843AE6FDAD55DC26A6A |
|
CONTENT
ssdeep
|
768:YslD0sJlAtkGwrhwySSk/9MxKxC2/KxCMqShS1+/DKiziyndhSktWfF:3lD0sakDSSzKxpKxaShS1+/DK6iyndhw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a9d6dd6a342f1149 |
|
VISUAL
aHash
|
ffff0c0703010303 |
|
VISUAL
dHash
|
213afaefd7d7e7b3 |
|
VISUAL
wHash
|
ffff0e072301230b |
|
VISUAL
colorHash
|
16c00010000 |
|
VISUAL
cropResistant
|
23d87ac7d7d7e7b2,4028dcdd2d0d1202,fdede7cacaeb73fb,1b2f6561c1c0c0c2,2141414145417171 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 48 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.