Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16152C8304040AD3601935AD3FB56970FA2A68349DF421B8AD6FCC3DAEBC9D44CD1A66C |
|
CONTENT
ssdeep
|
192:CukYwY/VTmOY2XgpdF34GJyY5n9FOlk4WPIjTOaP1/N:CMYTFoOyS9FOld4IjTf1/N |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92baed0be82dc22d |
|
VISUAL
aHash
|
ff0e2e2e0c2e04ff |
|
VISUAL
dHash
|
634cccccdcccdc64 |
|
VISUAL
wHash
|
ff0e0e0e0c2e04ff |
|
VISUAL
colorHash
|
020000c0006 |
|
VISUAL
cropResistant
|
432323414547455c,eee2e6f2f2e6a233,1844b191b2b2b218,34493252d2525214,3656c4d545e4e524,888a887131888a81,4400000080242484,5c4cccccdccccc5c,5184707179288441 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 49 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.