Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F0721BB9732422B1D90343D7ED2623FAE21790BD9B72569CD268821873858FD8973BC5 |
|
CONTENT
ssdeep
|
192:QopoBt50MdJnC4ByGLlKtiPTqdKcXnYRYku9cuGRmKbMpBXp7sfgg8gk:QCouunXykKA8XnYRjsmMpBZ7eg/B |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9f68c08b743c1fe8 |
|
VISUAL
aHash
|
fefe1f03a71ffffe |
|
VISUAL
dHash
|
70c033364c786882 |
|
VISUAL
wHash
|
3cfe0f03070fff00 |
|
VISUAL
colorHash
|
07000000c00 |
|
VISUAL
cropResistant
|
70c033364c786882,62669689891a98c9,ceb2b5143c242a0f,454533b4ec225545 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 487 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.