Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D263C62112481A3C361787E9F3E5B338506AD3C9D217996DF3AD02B25789E99EC3B3C4 |
|
CONTENT
ssdeep
|
768:eLBykW/wDLiBaBOpQBAe+rj0VCUhx8C0+p1AeWm30nSf7p7B7CQ7s1XeXl9l316D:Y5JKeZC/+nAeWzS2gFo3YGU7KksH1CC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3c43cb13cb5c3e4 |
|
VISUAL
aHash
|
123078606c6c0000 |
|
VISUAL
dHash
|
b6e0c0c8c8d83884 |
|
VISUAL
wHash
|
7e7c7c787c7c0c00 |
|
VISUAL
colorHash
|
38e00000000 |
|
VISUAL
cropResistant
|
b6e0c0c8c8d83884 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.