Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16F83C7B1A1202937025BA3E8AA127B2DB1C79347CF4147D481F1CF0AAFE6D95D8570EE |
|
CONTENT
ssdeep
|
1536:RslDNG3Cs9zHqDMbxWUcqT6cb4pX19pvMq:RuDQ3Cs9zHqA1WUxiMq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bbc4c448b53bd895 |
|
VISUAL
aHash
|
ffff8f8f8f8d8d8f |
|
VISUAL
dHash
|
682b191b1a39393a |
|
VISUAL
wHash
|
bec18f8787898587 |
|
VISUAL
colorHash
|
0f0000100c0 |
|
VISUAL
cropResistant
|
682b191b1a39393a,7cf830f098c9e171,7b6b6baaab2dbab2,e0d2d6b49671e8cc,b194dcdc9494949c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 649 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.