Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F9520BB4731411A0DA0387DFFF2222F6A103826EEE525D9CD3649618B3D9DFD8965EC1 |
|
CONTENT
ssdeep
|
192:Qo+oB6CJ54t9x3KQIB90/OHsUoh3bGwJ8EMku9cuGRmKbMpBXp7sfgg8gk:QPoCpYBu6sUoh3qRssmMpBZ7eg/B |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fca2d5a2d588d38a |
|
VISUAL
aHash
|
c3818181818181c3 |
|
VISUAL
dHash
|
2b2b2b33332b3333 |
|
VISUAL
wHash
|
ffc181c3c3c1c3c3 |
|
VISUAL
colorHash
|
0b0000001c0 |
|
VISUAL
cropResistant
|
2b2b2b33332b3333,aa80c04b33ca80aa,a280c04b33ca80a2,b6f068f2f0ecf0f2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 490 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.