Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T134446C77B26053A7910B47C5F8636526B76D20FF69460DD07328CDE4A35CCAEA8B3AC1 |
|
CONTENT
ssdeep
|
1536:h0OHMlR3qNKe3xfoma626INK+XJhMsDuNNK/zoUTMNKqNKqyNKUB+JNKunv//bK7:PlOhMsy6F6wiNkDShvOsN50Tstbq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96956c69626b6999 |
|
VISUAL
aHash
|
263e1e243e000434 |
|
VISUAL
dHash
|
ccfcfcccccaacccc |
|
VISUAL
wHash
|
267e3e3e7e240474 |
|
VISUAL
colorHash
|
30203000048 |
|
VISUAL
cropResistant
|
3b568692a3b39391,d8d2c6e9fefefefc,ccfcfcccccaacccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 67 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.