Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18E332371B9626539309F71CFC227170D62C3E7CAC7926BE685F052249AF5C94BEE3284 |
|
CONTENT
ssdeep
|
384:8FGYzr0eQtqe6xnN60i5y+4OJDDzzwe6z/aPMkHGnxGJToPIzr/4477UsyUeD6D/:8yeQts60icGheYJAyd77H1fxLNqOZF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d2cdd0f8d0c5d6d0 |
|
VISUAL
aHash
|
ff002c2000ff0024 |
|
VISUAL
dHash
|
50d969699923cccd |
|
VISUAL
wHash
|
ff003c3c04ff607c |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
04145818181b0000,1b1b5454a5e42b2b,f0e8cccececc7197,02c00b2b2b0fc000,b3bc3cfcd2929292,0090211e32222580,d496696969691900,0030c0c8cccdede9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 37318 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.