Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D6C385B1C006A537810362C2D77BB72A62B5D689CF525A0067F8C33A5FDADF59E23274 |
|
CONTENT
ssdeep
|
1536:/ebXGq78QmMkCR2dem37PykxzslD8jua8UHLlUDODUDhiUdDecH7djwDwSe64cI2:RWTs93Ge |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a2f25d7d051e9a13 |
|
VISUAL
aHash
|
80e3ff7767710000 |
|
VISUAL
dHash
|
0f0fcdcdcfe3e363 |
|
VISUAL
wHash
|
c0e7ff7767710010 |
|
VISUAL
colorHash
|
30200048001 |
|
VISUAL
cropResistant
|
f0e9a86289f2dc48,f8fca6eac932f1f8,0f0fcdcdcfe3e363 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 37 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.