Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B343762513082A3E651747ACF7A5B73892AED395D52F991EF27D12B253C7C88E8332C4 |
|
CONTENT
ssdeep
|
768:qWfhE3G3RO8nuvLzPIzO5W/AvGGGGm6Ivea5MPM+Q+A+P+76lepcbkr1x4kHqCb9:ZUvpGGGGob |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c10ab66c769661ed |
|
VISUAL
aHash
|
000020000000ffff |
|
VISUAL
dHash
|
c4c8cac8d2d30c0c |
|
VISUAL
wHash
|
00087a7e6840ffff |
|
VISUAL
colorHash
|
02000006000 |
|
VISUAL
cropResistant
|
3667e65746d59798,c2d2d3ebf4c6ecd0,8dcd5035b6aba5a5,494dcdadc9e84d4d,00000d089e0e4c00,c42ccacac8c8d393 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.