Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16B33F8B120910AAE91134BE0F5B9F36DA0E7F14DDF57A658E39C11E20BCEC58BD26358 |
|
CONTENT
ssdeep
|
768:VqC6KQ6Ka6Ka7/1Lys0GeFaWjfipYpSfipOp2p4Ap/pPwp8pD7pnpPzp4ppjOTCF:UdjMs0GdWr8JU9x/WVM7I |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
84c1ce8f6b8579b4 |
|
VISUAL
aHash
|
ff7e664006063600 |
|
VISUAL
dHash
|
c28494818ce6e6a8 |
|
VISUAL
wHash
|
fffee66006063630 |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
c28494818ce6e6a8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 492 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer checks balances of popular ERC-20 tokens (USDT, USDC, DAI, etc.) and only proceeds if total value exceeds minimum threshold.