Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E030B70A454DD2740DB99E66236A626A1FA8348C51316C8FAF8C3F91BEFC6DDB33114 |
|
CONTENT
ssdeep
|
768:QlsIx/jlTb6vBLzwVLWtpz5Xr5hcEceGdkS8U+Uf7Cd417G2w:QlsIxhf6vBLzwVLWtpz5Xr5h1ceGdkS4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed12ed92522d926d |
|
VISUAL
aHash
|
ff0000003dfffbfb |
|
VISUAL
dHash
|
63aaa29cc9403272 |
|
VISUAL
wHash
|
ff00000014fffbfb |
|
VISUAL
colorHash
|
030020001c0 |
|
VISUAL
cropResistant
|
00436373736300de,8962603212326262,00118ee6e6e61940,9eaaaab0849c98e9,dd5fe5859b964d13 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 48 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.