Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19A92A5707600143B11274AF6B460FBBA71DBEB99CA479549F3BCC2976BCAC80DE21364 |
|
CONTENT
ssdeep
|
384:QRZCUlKBxn57uZSMyVStGcoHHnBbuhCKI:QSBVRu7YceA0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e45c715b53535744 |
|
VISUAL
aHash
|
00d372ffffffe3c3 |
|
VISUAL
dHash
|
d89696e618625555 |
|
VISUAL
wHash
|
004240fbffffc581 |
|
VISUAL
colorHash
|
06403000000 |
|
VISUAL
cropResistant
|
8080c2c2c2800080,9696960988575555,03d4c0c0d0239090,46864367b65b5353,0f33336955d6553b,162132338e962222 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 13 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.