Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16FE229B4A230E335B1C247E8DA6425687A5FE1DCD7C695B0E388AF51B0D6CECD9160CB |
|
CONTENT
ssdeep
|
384:Y7fUWeguzjf4aRhiXkdvNTDhPhLxeAxeDWNW1Tp34PxeeJEmuW3As2aRWoMd:Y7fUWeguznhhPhleMeDGCSPxeeWmHrW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3dd1cf068276363 |
|
VISUAL
aHash
|
901e686060640600 |
|
VISUAL
dHash
|
7474cacbcbc84cb1 |
|
VISUAL
wHash
|
f03e6e68e86e2f40 |
|
VISUAL
colorHash
|
302020000c0 |
|
VISUAL
cropResistant
|
f9f83cece67f1e1e,f0dc4c6cf2ae8491,03c6b8a0d4d4e979,7474cacbcbc84cb1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 73 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.