Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1037352B27142582F66AF82CBE11B2F0CE1C1D3CBC2511ED9FAF441659BB1E74BD62260 |
|
CONTENT
ssdeep
|
768:JdylRTrIhd8JhqTdiJaDZKELtK4idPOgKl2dhX:X4RTEh6JhqTdiYlKatK4kPilSX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a163cca9da58dcca |
|
VISUAL
aHash
|
ff000000030309ff |
|
VISUAL
dHash
|
23cece8e1b5a73a4 |
|
VISUAL
wHash
|
ff2303030b0b0bff |
|
VISUAL
colorHash
|
0e206000000 |
|
VISUAL
cropResistant
|
20232321569e9e9e,a280836d658080a2,7f792637b7b3e98e,cb65e7f3f3696cfe,33c0a424ace0ece4,cecece8e1f5a5273 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1086 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.