Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E7225430511CAD3F914A42CCA7A3B72A32CE43CDCE5A431571F48B6C8ED2D95EC6A2B5 |
|
CONTENT
ssdeep
|
96:/tuHkPbbHfGNsZshZgO1Kkfd5s0l1Vd3+LTL6U/13rsoWKx:/QknuqOCO1KmDZVdyqUt3rsoWKx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c23728cc93366dd |
|
VISUAL
aHash
|
0101031b1b1e061c |
|
VISUAL
dHash
|
ffffdfb3b2b2ccf8 |
|
VISUAL
wHash
|
0307071f1f1f1e3e |
|
VISUAL
colorHash
|
18000038000 |
|
VISUAL
cropResistant
|
c2f6b6c2c0016182,ffffdfb3b2b2ccf8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.