Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AC637D20A6C82167027BDCC09D207F5D21D2E36BC117D1565ABC92540FD3EA3FBAB9B9 |
|
CONTENT
ssdeep
|
192:AXklzdHGm2ib+EZ97v4YJ+tV/8+JgaMmE9yAHHXqr5hdlFM4iTfOGfNdgavGP:4tE7r4YJSh8Yc/H3qr/T/wOGfNdgavGP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
97bd6832934b6c1c |
|
VISUAL
aHash
|
67ff9c6e2e000000 |
|
VISUAL
dHash
|
cd5c30ccdcccccc4 |
|
VISUAL
wHash
|
6ffffe7e2e040000 |
|
VISUAL
colorHash
|
180030000c0 |
|
VISUAL
cropResistant
|
bc28606220f4b4bc,8080c0c5c1f4f4fc,c6e4c6c7f5e26227,cd5c30ccdcccccc4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1084 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.