Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AC235F709441AA3B02A396E1FB711B5FB3D2828ACE630B0523F8C75A5FE7D59DC17264 |
|
CONTENT
ssdeep
|
768:YoejSyq9PwtQjPc9MC1OMyumByFViy34SSGDh4ysopA2Xe+Ddl4:YFjRqlwtQjPTC1OMyumByFVX34SSGDhe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9303c50ef38375bc |
|
VISUAL
aHash
|
3c1c000c0000ffff |
|
VISUAL
dHash
|
e8f8c9c929796900 |
|
VISUAL
wHash
|
3e3e0c2c0400ffff |
|
VISUAL
colorHash
|
02007000000 |
|
VISUAL
cropResistant
|
fc00c09090c000d4,f0fcd0e8aab9f1f1,99913333352bd2d2,3724ec3eb2aca6ba,696927161700020c,e8e83bc9c9291b69 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 54 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.