Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C6D3846863161936D00B47E4BA31E67D719FD1CEE1A7B21CFA6C8022368ECDD9C606DD |
|
CONTENT
ssdeep
|
768:yRn+OzCUPOc5LkutGsI/C9+pn3Z+5DLCzCrfmFfPzdKG0YsrHxcUuc+yKlnRkvqt:yXg1Vp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9f92db912299ee11 |
|
VISUAL
aHash
|
3e3e1c1e069b1e81 |
|
VISUAL
dHash
|
f87870f0dc36126b |
|
VISUAL
wHash
|
3ebe1c1e0e9a1f81 |
|
VISUAL
colorHash
|
32206000000 |
|
VISUAL
cropResistant
|
3e1cdcdcb8b0b858,8ccc4c8cce7cccec,f87870f0dc36126b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 26 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.