Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T189F32A3432086A3E5A7383EAB1DA7315A278C35EC11B4964F3ADD5B623C9C96D437BC4 |
|
CONTENT
ssdeep
|
3072:wtOk6+W0b5TQoLVO9XiBTMYmL6Cstn97ZGl+:wtOjeO9iB4Jxstn97ZGl+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
895623dcad56a95c |
|
VISUAL
aHash
|
00003c3c3c180003 |
|
VISUAL
dHash
|
8433686871316833 |
|
VISUAL
wHash
|
7a383cfc3c1c3c13 |
|
VISUAL
colorHash
|
38000000380 |
|
VISUAL
cropResistant
|
8433686871316833 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 359 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.