Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E8B250F2C0008837064366E6B626274DA9A3C34BDA521E595AF4071DFFDADE9CE0797C |
|
CONTENT
ssdeep
|
768:KyivaZmF7JeFP2vBI230a+hisvlZGg4YEYVeKDd4V6mD:dQaZmBJeFP2vBI2Ea+hisvlog4YEYVex |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c915f236a3b19974 |
|
VISUAL
aHash
|
003c387e0038f8fc |
|
VISUAL
dHash
|
9cd4f0f0b0f08080 |
|
VISUAL
wHash
|
007c3c7e1038f8ff |
|
VISUAL
colorHash
|
01006080000 |
|
VISUAL
cropResistant
|
9cd4f0f0b0f08080 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.