Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11CC23061B942716702B794C0F820BF897AEAF30FC299949637BD09E2CFD7EB47046561 |
|
CONTENT
ssdeep
|
192:6KVRz57luyFGF7MF9FZF5FT6mS4AJMrTtke+QjFZB3c7XjR//x//x//x//aig2:9lBFGF7MF9FZF5FTnzx8bj/3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e6cccc668c668ecc |
|
VISUAL
aHash
|
f7e7e7e7e7e7e7e7 |
|
VISUAL
dHash
|
044c4d4d4c4d4d4c |
|
VISUAL
wHash
|
c3e7c7c3c0c4c0e4 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
044c4d4d4c4d4d4c,502c5269696d1640,1fbd9d9939693931 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.