Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T146C38532D219987FD14B807CE6D4946922FD92EFF1D0C3A4B57D2F1DA4798E2488E788 |
|
CONTENT
ssdeep
|
1536:WyFE3HTifvpGYvHvy7pamc2fz3wPUygKAjq0MO+IogHY:WyFEXr8kfHY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b6b4c74a3cb443a5 |
|
VISUAL
aHash
|
6707070707050737 |
|
VISUAL
dHash
|
8e0c0f3f3d79ec4d |
|
VISUAL
wHash
|
77870707070507ff |
|
VISUAL
colorHash
|
07001000180 |
|
VISUAL
cropResistant
|
8e0c0f3f3d79ec4d,ae1e3bf3367c2d8f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.