Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1538309B1B28021FB2153DBD4E2327F38756372FECA494581B2650AD467F2DBDE81B990 |
|
CONTENT
ssdeep
|
1536:QTKc+QNW90wmgven73nWvfRjitjQ+yorfLwzdvnGhbooZ7QrC1yBuIjitjQ+yorG:9ven73nQfRjitjQ+yorfLwzdvnGhbowg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9293cc6d6ca8d5c6 |
|
VISUAL
aHash
|
186e7e0c00000100 |
|
VISUAL
dHash
|
33cccc8940c88905 |
|
VISUAL
wHash
|
fb7e7e6e40605501 |
|
VISUAL
colorHash
|
380000081c0 |
|
VISUAL
cropResistant
|
605b40a2a0525be0,a280d01a2aa280a2,6f763eacd4d06464,33cccc8940c88905 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 218 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.