Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T187C306B55091253F10378AE5B1A5E35AA0CAC31CDF93D494B3DC53662BCBCB2EE1A16C |
|
CONTENT
ssdeep
|
1536:S4ujQVnDl3e7enzc4vuCuU3cn8rFsf4/Irwyfzla3OXWDb8wyr884TWtVwIRJlaI:nlxvuCuUWtPH+OkyGREUUsA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc332799893353d9 |
|
VISUAL
aHash
|
819118103c181818 |
|
VISUAL
dHash
|
332333a0b2322032 |
|
VISUAL
wHash
|
ffdb98183c18383c |
|
VISUAL
colorHash
|
380c3000000 |
|
VISUAL
cropResistant
|
8208104d4d081082,332333a0b2322032 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 681 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.