Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C632A52162090D7E35335FD9F6A37338D09A9358D68A2824A27F437487C9EACF8379D5 |
|
CONTENT
ssdeep
|
192:eHgACA+AlBZuahRxENQm89x0o8uoCLJu9Hp1hXBLsK/9JNe:0H5Vlvuanx1v0o8u99mr/LsK/9JY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc8c8ddcec989c66 |
|
VISUAL
aHash
|
3c3c3c3c383c1818 |
|
VISUAL
dHash
|
f1f0e0f0e0b0f0f0 |
|
VISUAL
wHash
|
3c3c3c3e7c3c1c38 |
|
VISUAL
colorHash
|
380020001c0 |
|
VISUAL
cropResistant
|
603038dc96deecfc,f1f0e0f0e0b0f0f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 190 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.