Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E2E2F871A24051E703B3D6C5E660BF1E7697F33F804A86A66AFE91951FC3E78BA01071 |
|
CONTENT
ssdeep
|
192:69VRtR19BoNlrIAFeQFUBFthF8MDw9DXIIwQu0nHYO9bNsBp+Oxe9MoSfp1VBBCE:Sv1zoNRIAFrFUF/F8MeE3zd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
921d1d32ace5e6e2 |
|
VISUAL
aHash
|
0000ffff0041ffff |
|
VISUAL
dHash
|
f8f84d008d8d00d4 |
|
VISUAL
wHash
|
0000ffff0000ffff |
|
VISUAL
colorHash
|
060010001c0 |
|
VISUAL
cropResistant
|
f8f84d008d8d00d4,b7c0efbfdd79a989,cc00cc4c48418086,91b313a7b793929a,f6f4f4f4f8f8f2f6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.