Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11B3464613A02792631AF42CFD2371A1D21C5E7CEDAA26AE5D4F0C32499FAD90FFD1251 |
|
CONTENT
ssdeep
|
1536:Jn7IL7R40LM7I0qtbF4dVQRFDRkZkRIyIWPeoS0n7IL7R4FLM7I0qtbF4dVQRFDi:b7F7SR7Sz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e6b31b4c1b4e3266 |
|
VISUAL
aHash
|
00ffe7f7e3c3f3f0 |
|
VISUAL
dHash
|
410d4d0e86864624 |
|
VISUAL
wHash
|
00efe7f7c3c3e080 |
|
VISUAL
colorHash
|
07c000000c0 |
|
VISUAL
cropResistant
|
410d4d0e86864624 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 117377 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.