Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12F0208F26220972E04C7C5BCFF62F054928EE19EE657C9D0E6DD83A519DBCC0FA52A10 |
|
CONTENT
ssdeep
|
96:TGu33x/7eS7X7D7BiGVCJc+aAXXwg2+3wehaBQ8VjKx3NuZkTmB0qMcSPWSic/Ct:augCViJLaPjywAcQSyUZxBcFL/W |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99996666dc13cc6c |
|
VISUAL
aHash
|
0000181818180000 |
|
VISUAL
dHash
|
2814b2b2b2b2300c |
|
VISUAL
wHash
|
00ff18581818003c |
|
VISUAL
colorHash
|
00000000007 |
|
VISUAL
cropResistant
|
891669499eb25a5c,b29aaa86aa8e2b2b,2814b2b2b2b2300c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 64 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.