Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B7C43CB1A0102D3B01DB83D4F6B86707B3F4D349E60A45925FE8DF982FE6E60DA1A45D |
|
CONTENT
ssdeep
|
6144:ngNyFesw/292p6JXyZyoV7/06iwJIu9s19z04yzCcoI:CyFesw/292cXyZyoV7/06ieO1cpn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fe82c3b48c196a3e |
|
VISUAL
aHash
|
ffff808087878df8 |
|
VISUAL
dHash
|
710d39392e3e3931 |
|
VISUAL
wHash
|
ffff8080878780f8 |
|
VISUAL
colorHash
|
0f400038000 |
|
VISUAL
cropResistant
|
710d39392e3e3931,53632434346460c9,0020048e8e068001,4b2727d9d1514b07,415b167a335f4fed,414586b0b0c88e3b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 769 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.