Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D7D3C778A0733B5B0F2AD2D51DA147A5BCA71C2D5F70B23CCDF6C131BA288DA44E5926 |
|
CONTENT
ssdeep
|
1536:u1xM0FCTgBB+/MR0FCTgBB+/MsIFJTTw7hlphdShtNhRohEVytPhIhvBF:u1xdOTvBF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c767659638393992 |
|
VISUAL
aHash
|
207020003e3c3420 |
|
VISUAL
dHash
|
ccc6c0d878e0c4c4 |
|
VISUAL
wHash
|
7070203c3e7e7e3c |
|
VISUAL
colorHash
|
38e00010000 |
|
VISUAL
cropResistant
|
ccc6c0d878e0c4c4 |
Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.
Malicious code is obfuscated using 879 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.