Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1108274319048AA3712A391D1FB31274EA1D3830ACF232BAA77F8C75D6FC6D95CC26255 |
|
CONTENT
ssdeep
|
192:MsNuJ36oqnJAQDHAwSdsDGkLBss8RyhLH9AWZRx1k4WP4JhaicJaPZQF:HNuvqFgtsDGX1WZRbd4yhaf2ZQF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
95b14aeac9ec94c9 |
|
VISUAL
aHash
|
ff060f0f0f060000 |
|
VISUAL
dHash
|
9cdcdede9adcb251 |
|
VISUAL
wHash
|
ff6f2f1f0f0f0000 |
|
VISUAL
colorHash
|
00000007000 |
|
VISUAL
cropResistant
|
00006a676a4a004e,f0f0f89cdc9edae6,ccdcde9ade7c3251 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 34 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.