Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DA63A7B281781C3952D7F3E4D652BFACD3C34307D6898BD3D5A2CF892A84D57A647228 |
|
CONTENT
ssdeep
|
1536:0q126rUXCX56bsWW0MbrJOidVy4VymOnGMdVJ8IFfOu6sjJzwMDGw/Io6UhJiOMA:x12c6bsWW0MXR+jVwMDN3h0O |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b04f4d304f734fb0 |
|
VISUAL
aHash
|
00ffffc7c7c7c781 |
|
VISUAL
dHash
|
881e050d2c0f1c1d |
|
VISUAL
wHash
|
00ffefc0c7c7c700 |
|
VISUAL
colorHash
|
06000030000 |
|
VISUAL
cropResistant
|
161e050fae0f1c1d,469c968244a9a919,1089b23230081000,0faf9f2e9f9d1c1d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 279 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.