Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D3D2A362524C2F7DA517C6E8FBA1B334126AC28AE26E9128E57D13B05787C89F8335D4 |
|
CONTENT
ssdeep
|
192:arXq/DvUe4SXwnUc1+UUWdoKJsSrwXHGiVHsajRs7nfVYgQIe4SywkkrVUqs76sD:yywyWWlfj4dYgHkJVptppJa2NjaNcFK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd32771b5d186722 |
|
VISUAL
aHash
|
00a5e7ffffe7fffa |
|
VISUAL
dHash
|
794c4db2b24cc996 |
|
VISUAL
wHash
|
0000e7ff3ee72752 |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
4c4d4db2b2f24c4c,0080808080028202,00102c2d2c242c10,0000020109090901,1471694c4d4d4d4d,000004000c6d4c90,0020586969680400,4c4c0888c0c8b696 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.