Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T164E249B4A230D335B1824BE8DA6424687A9FE1DDD7C694B4F388AF11B0D6CECD8150CB |
|
CONTENT
ssdeep
|
768:Y7bPhOJeguPphhPhleMeDGCSPxeeWmHJW:0GGpxFWoW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc66b13699748967 |
|
VISUAL
aHash
|
bff0b0f070f0f0ff |
|
VISUAL
dHash
|
26246561e1a464b2 |
|
VISUAL
wHash
|
ffb0b0b030b0b07f |
|
VISUAL
colorHash
|
19202008080 |
|
VISUAL
cropResistant
|
902b2ba9595d5d1d,185a5acbca8a9a99,a6a7a75050505051,29696969684bd279,c8e0f0a869edb733,9292d2f27260e7f6,a2a68e9c1d3c58da,26246561e1a464b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 208 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.