Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CBF23F309000993742E3E2E1A635676BB3D1834CCE531FA167F8C75E9FE6DA4ED12A64 |
|
CONTENT
ssdeep
|
768:z+Y0A+8YXHPMlXKCTZMYDsCeeeAOfHptpx5GcGVQl0iUNRuyUf7k:z+Y0A+84PMlXKCTZMYDsCeeeAOfHUROY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ccb7a14ab2686765 |
|
VISUAL
aHash
|
40fef0fef0f0f8ff |
|
VISUAL
dHash
|
9982222420609182 |
|
VISUAL
wHash
|
40f8f094d0f0f0ff |
|
VISUAL
colorHash
|
07400008080 |
|
VISUAL
cropResistant
|
9982222420609182,0000000000000000,000854a4a44a0000,34326070343545c0,2000000400041818,c02120129bc34b48 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 39 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.