Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T115E2F031B400A5331A73D1D697322B0FA2C5A245CD772986EAF887B97EE3DA9DC13714 |
|
CONTENT
ssdeep
|
192:MTv6ydv7Eu8uTOz07OzMOs5Pl6L16275XZwnP0xHXmTMNcSMfPNA8Zkjz6ik8Gf3:MTv6UAz0Ssdg5Gen6ik8Gd0qHYFCh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c0e0283d3f1fa7c6 |
|
VISUAL
aHash
|
03f0767e66200001 |
|
VISUAL
dHash
|
b6848ce8cccb30b3 |
|
VISUAL
wHash
|
43f6fe7e6e001843 |
|
VISUAL
colorHash
|
100000001c0 |
|
VISUAL
cropResistant
|
88cae4a6a6e68d93,b6848ce8cccb30b3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.