Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F12344B1D180A827505782D4E172672A33714381CF435F5167F893FBBE9AEB1EE72289 |
|
CONTENT
ssdeep
|
384:C8J7n9OdhREINgIaFvxPznGGxUQrNz3cdKd41mUIN:C+7n9OOIN7aFvxbn3N8Kd41mD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9639399e65619c39 |
|
VISUAL
aHash
|
1e3c00601e3e3c20 |
|
VISUAL
dHash
|
78d8f9cff4e4ecc5 |
|
VISUAL
wHash
|
9f3e30601e3e7c34 |
|
VISUAL
colorHash
|
0603a000000 |
|
VISUAL
cropResistant
|
30646afcec08e9f3,3074ecfcf450e1f3,306cf2fcfc68c9f3,78d8f9cff4e4ecc5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 311 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.