Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17B151AB0A0107D7B01D783D4F7A46B0BB3D4D349EA0A45625BE4CF981FD6EA0EE1A52D |
|
CONTENT
ssdeep
|
12288:QHwenw+280g5yZynVz/jqe251pETC+h1EfdGNA6yUyYVl/aNQO:penwi7kEPh1EgjU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
85487ab73f43594c |
|
VISUAL
aHash
|
0018787a7f776600 |
|
VISUAL
dHash
|
8eb2f2d2f6c6c6cc |
|
VISUAL
wHash
|
001e787a7f7f6700 |
|
VISUAL
colorHash
|
32601010000 |
|
VISUAL
cropResistant
|
0000000000000000,8197c4c4ccfcc5c4,008084b8a998ecac,12062131696464c9,00000c0c0c0c0001,060691920cc00000,f2f2d2f6d6c6c6cc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1096 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.