Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C5B318393E03247B6437A4F0E45A2E1971A38F35C267BD65639C57360FDADE4A9E2320 |
|
CONTENT
ssdeep
|
1536:BewWgnz5THLBXGpK7LWagfWbQhQlBqYZBLf2wLfOELfEjLfgNTzhBeC3X:jzJrZmci7BGjp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
90a03f5b7425137f |
|
VISUAL
aHash
|
00ffff437c08a700 |
|
VISUAL
dHash
|
fd708f86f8d84d2c |
|
VISUAL
wHash
|
00ffff42fe088686 |
|
VISUAL
colorHash
|
06403000000 |
|
VISUAL
cropResistant
|
fd708f86f8d84d2c,d8f8795d6ded49c9,0000000000000000,0000000000000000,07173f9edf5b3f3f,3b59b586a652c9c9,54d4793133321213,64e8bc9cd8d95bc3,584d090f2c646e6e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 67 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.