Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T117721F1090995A3710B381D2F6FAAF2AB1D6D1A4E36B064493FC4B5F1FCBC18FC1A656 |
|
CONTENT
ssdeep
|
192:c2WY8ewxKIbvBZO2DGZNHstfyeNND8/1gGuTNwpQ/jgd:58e4KIbvBZOhMtM/luTepvd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
952a0055eacdded6 |
|
VISUAL
aHash
|
0000ffffffffffff |
|
VISUAL
dHash
|
b39d00550c8c8a84 |
|
VISUAL
wHash
|
0000adff247e7e76 |
|
VISUAL
colorHash
|
0ec00200000 |
|
VISUAL
cropResistant
|
b39d00550c8c8a84,38e2c12498e1c6c0,c015b4f09bdb9494 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 21 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.