Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A9821BB26040243E06AB46FDE256FF7C61F65215D7190880A6FD229B4FFBC54BC3B18A |
|
CONTENT
ssdeep
|
384:qY+JobIkEEUykwyjgotLc2XewFJ+RQ6/mLdWHYc1RcWx:XjSx3+RQEEdgYw3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dd1c267f582b2964 |
|
VISUAL
aHash
|
00383bfefef86070 |
|
VISUAL
dHash
|
70e0f2b2305042e0 |
|
VISUAL
wHash
|
003839fefef8e070 |
|
VISUAL
colorHash
|
030020000c0 |
|
VISUAL
cropResistant
|
f8e8ce9e51317919,30f0b999184941e4,7078f8fcb85c35b3,70e0f2b2305042e0,764b7d37170d0325,7d7c7c1f0f0d9e96,1d7171571b0f0712,a7b797d6767bfbf9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 964 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.