Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C5E3C7707E736422216F62DF80175B0E62C3C7CADB93ABD562F082189BB5C847F93596 |
|
CONTENT
ssdeep
|
1536:lj63hoF8AdICDnu/Io8CwbrGFkeafYGWY54x5F5a8ayYF7hp8LuLUgSCEyS1g2rN:DGuYGWY5ENYF7bE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc38a3c7471ec178 |
|
VISUAL
aHash
|
00000000f0ffdfff |
|
VISUAL
dHash
|
2d35312b22143020 |
|
VISUAL
wHash
|
04000800fdffdfff |
|
VISUAL
colorHash
|
07c00000080 |
|
VISUAL
cropResistant
|
2d35312b22143020 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 651 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.