Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EB43FB37C25481315F5B83D8D1F15F183089808E1B61BAA4E67AC3B6FBAEED85C7149E |
|
CONTENT
ssdeep
|
768:b6dAezSWwbRBV2nCH8B8AIS6jiFlcdopWRNO4MhtHxKTrpwq2ad72Qd6A:O/nCH8B+4pWRovfxKT+XaV2dA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e6399c99c2c363cc |
|
VISUAL
aHash
|
ff8381e7e7e7ffe7 |
|
VISUAL
dHash
|
8e370f4f8c8e0c4d |
|
VISUAL
wHash
|
76818183c3c3e7e7 |
|
VISUAL
colorHash
|
071c1000000 |
|
VISUAL
cropResistant
|
8e370f4f8c8e0c4d,007842a513063001,80784225a3cef8c1,70c49aa58c8ad4f1,cfc1dcc1c7fcc1da,3b663273673f1f1f,933144ccccdc7117,d5d2c0dbd3c0c041 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 70226 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.