Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DC269EB17361B03957DB52A9A46F0009F33D5C48A40D407CF3E9D8EB68A89C991BBF79 |
|
CONTENT
ssdeep
|
49152:IEpYXAXoNXhzjCAyVP/QZMP/3w4L4+2n8S+9rAA9dT9DWwjjVvP3Ty3Jz7HxC7Aj:I3djCAyVAMPsyjhtX6J |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9cbc33b68cb9328c |
|
VISUAL
aHash
|
061818183c3c1800 |
|
VISUAL
dHash
|
169233b2b271318a |
|
VISUAL
wHash
|
c718995a7e3ebd00 |
|
VISUAL
colorHash
|
380180000c0 |
|
VISUAL
cropResistant
|
312b6d3131c9e96e,169233b2b271318a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1631 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.