Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T128A1A63112050A1F56275791FBA1F768A0ABE35CC90B986CF0FD21F513C2EE09CA72E9 |
|
CONTENT
ssdeep
|
48:TxCc2PRTNmMe4gu1vBU5ksAQ9a9yoL0iebzsp5st8cB94rV8c6BM4R3SW/3ct8mw:T8tPrSAQ9a9y8n0zsST4J6BP3/stOQhI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dddc6223998cdc89 |
|
VISUAL
aHash
|
c0c0d81818180000 |
|
VISUAL
dHash
|
2020323232330303 |
|
VISUAL
wHash
|
fef8f8f8f8d88000 |
|
VISUAL
colorHash
|
00000600018 |
|
VISUAL
cropResistant
|
2020323232330303 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.