Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1618264B38C43E01F965B54C9E5309B2DA997AE2EDA234D80A3FE4BD3F7C4D86C601585 |
|
CONTENT
ssdeep
|
192:6T9WhB5fVCMt877TCiwBkzBVXKAv9G+Ivv6aB7jYxIz7y6BsWpfMSygy:ruIuzXKAvs9Je6BfBRy7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d4bf413e4a3e11d1 |
|
VISUAL
aHash
|
00fffe979602547c |
|
VISUAL
dHash
|
b1a2b824acacaad8 |
|
VISUAL
wHash
|
00fbfed71604547c |
|
VISUAL
colorHash
|
06480000200 |
|
VISUAL
cropResistant
|
f4b4b4b4b4b4b4b4,b582ac24acaca8d8,b9b0e4444ccce0f0,7a787ce4a494f0e4,b4b123b9b2b9c9a9,16484849c8544340,371f998381331ebc,d8f0a9a9a9e9f1f0,5bd2b333b2303233,7161cc99dd591993,4f61b1a3c70db1f9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 30 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.