Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E2A3EE61244956AEF7534AFCF0901E67A243FF2DC62130C5D3D993A512FAD72E21A38D |
|
CONTENT
ssdeep
|
1536:CehMRUUfIMeTvZc85PgQMr4TVGUbmw+IonFYZF:CehDcPq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
929f6e60680f1dec |
|
VISUAL
aHash
|
007e3f1f67060000 |
|
VISUAL
dHash
|
1dec78f99d8c8dac |
|
VISUAL
wHash
|
00ff3f3fef064600 |
|
VISUAL
colorHash
|
1a002000080 |
|
VISUAL
cropResistant
|
e6667272b2a99393,1ed5555c9c952f6a,1dec78f99d8c8dac |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 182 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.