Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1119429A053902ABB45A747E9B230B35AE19B537AD723D88CF7EC47569FC6C2CCE11190 |
|
CONTENT
ssdeep
|
3072:g1gulg2fBMtEf9F5UTLXUTK7ZbZtXZeiHPCuuUZs5RwL4ZujVgub5tIZ/rvLfqLH:g1j2LX2sv5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c56afa35456a1cb1 |
|
VISUAL
aHash
|
00fff0000000ffff |
|
VISUAL
dHash
|
c89f21c6d6d62f34 |
|
VISUAL
wHash
|
64fff0000200ffff |
|
VISUAL
colorHash
|
12602000000 |
|
VISUAL
cropResistant
|
0084492b2b628000,031b130017170201,e08c332b29338ee0,809b496d60696080,8b332a593c3b3c34,004833cccc832800,a160e1c6c6d236ce,8e3369296961338e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 48 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.