Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1030320619901B679412BA6D1E021BFCD76A3E38BE306040C5BFDA7569FCAC7067439F8 |
|
CONTENT
ssdeep
|
768:OvGINb6/H06RYwWKtHDTkF302tiCr97+xgVoc24889aLKpCkWd7/3SgEhbBhbnh5:OvGINb6/H06RYwWKtHDTkF302tiCr97f |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c3a6be32bc48cca |
|
VISUAL
aHash
|
81081c16027e7e34 |
|
VISUAL
dHash
|
13393434b2e6e4e5 |
|
VISUAL
wHash
|
811c1e0e5a7e7e39 |
|
VISUAL
colorHash
|
38002088000 |
|
VISUAL
cropResistant
|
13393434b2e6e4e5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.