Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14761AD628806651B121343C4793ADA9F65C3A30DDF720D4167EC03EF67DED5B9CAA294 |
|
CONTENT
ssdeep
|
48:TxfspTQqu9BjG9Wb9ZwZTaATfCu04+J1Vim8vbV3I0L8SQH8ShES9o8SPwSogS1b:K6ycGPTK5Ap3AS5SGSVSoSJSKUQY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b238c1c7cdcdccc4 |
|
VISUAL
aHash
|
cf878787c7ffffff |
|
VISUAL
dHash
|
1a0e3c3c0c4f7000 |
|
VISUAL
wHash
|
838783870003ffff |
|
VISUAL
colorHash
|
07200008400 |
|
VISUAL
cropResistant
|
1a0e3c3c0c4f7000,30b4b0e0b0b0a8e8,e9a1b54fb2c6e3e6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 51 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.