Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E7C31AF0639025E4D50793E9F631A768321791BEAB46CA18C3F41E95AFC6C9CCD818D7 |
|
CONTENT
ssdeep
|
3072:/OEoYHFay3OtKTKmQw/udmQtbb3hxVE4rnn+J0PlYrCCfOyArFH9tr/W66dMeO:/OEoYHFay3OtKTKmQw/uP7hxBUcFn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92126ced6d8313bb |
|
VISUAL
aHash
|
00000400ffffff02 |
|
VISUAL
dHash
|
25cccccc332020d6 |
|
VISUAL
wHash
|
00040400ffffff7e |
|
VISUAL
colorHash
|
33200030200 |
|
VISUAL
cropResistant
|
b879b9b0b692b666,8282c252528280a2,0b2b03203030200a,233dcccdcccccc34,014626d6d6364601 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 52 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.