Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T191F1B7212200593F65234AD9F6E5F26D85C7F34AC127CC6CF1B9136A26D1ED0D833AB9 |
|
CONTENT
ssdeep
|
192:sbKiTjQnLVTQkMRsHsjDlGry3RRYvsoaO:QKeknLXKuy3RRYhaO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed67e30814b1b999 |
|
VISUAL
aHash
|
e060c3a71818ffff |
|
VISUAL
dHash
|
06c00b2e32b3080d |
|
VISUAL
wHash
|
e060c1a71818fff7 |
|
VISUAL
colorHash
|
070000084c0 |
|
VISUAL
cropResistant
|
0006161616060000,c4cb0e6c33b3080c,654404c4c2c1c9c9,a5b5b1b1c343ce8c,cdadf1f1cd421a2e,acacb5b4d42deaca,a3a32da5ab69e6d6,ced79b2b05454520,05c1450d454545a5,2b23654545616161 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 108 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.