Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B9A3A5716143AC378553D2D0E2316B5EA1C5A30DCB120D56FBF8876AAFDAD74FC2A1A0 |
|
CONTENT
ssdeep
|
1536:eS/B44TGq0gAjkG1Bzz9oFY6pazzqOQWLn0gAjkG1Bzz9oFY6pazzqOQWLXBZXCd:VGyLJsj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd90b287d69c73c1 |
|
VISUAL
aHash
|
ff3f001272333900 |
|
VISUAL
dHash
|
f87a7226e2e2e341 |
|
VISUAL
wHash
|
ffff121272327900 |
|
VISUAL
colorHash
|
07e00008040 |
|
VISUAL
cropResistant
|
f87a7226e2e6e3e1,cde7f3f3f9fc7ccf,6767666464367e3c,7af226e2e6e3e349 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 119 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.