Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T161F2652823482B2D665787E8F6A5B334D279D698D32B991DF2BC01F20387C45D9377D4 |
|
CONTENT
ssdeep
|
768:+IQ5C4NpaNXnWQPnA0Ubypg/rGp9UzGcK/li+M9BuO6Etrj/+Xhqks5C9b2CSsnQ:+IqOWQPW/rGpF85C9S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cec3313ccad3ce60 |
|
VISUAL
aHash
|
40003c3c18180000 |
|
VISUAL
dHash
|
8816e06020a458a5 |
|
VISUAL
wHash
|
7e407e3e3e3c1838 |
|
VISUAL
colorHash
|
38e00000000 |
|
VISUAL
cropResistant
|
8816e06020a458a5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.