Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T123530070A085AF3B40CB58D6917B572673E1830AC3271689BAFD97EE0FCBC28D663154 |
|
CONTENT
ssdeep
|
768:AGsIx/jkI/v8+2fGrG+GAs6RtH8MRphIGUf7k:rsIxU+2fGrG+pXDH8MRphIZ7k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9212f3e96963c715 |
|
VISUAL
aHash
|
0000000000ffffff |
|
VISUAL
dHash
|
cdececcdd30c0f17 |
|
VISUAL
wHash
|
000404003fffffff |
|
VISUAL
colorHash
|
030000001c0 |
|
VISUAL
cropResistant
|
e1d8ec64b42c6c36,4a004d0f3307162a,cccdecececcddb3f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 55 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.