Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T135B43031A2726937421B85F9B2B00E1D6242C3108B0799B1CBF57BB36B87CA97F55B4D |
|
CONTENT
ssdeep
|
1536:zmFZLAt/Q6wxZoV/4qHBm+xSc+4I3MxuoWL+35EWTti9W0LxLKg3V0T3TWoagwV9:yLAt/Q6wHkqCBLAt/Q6wPtFB5HmK7VP6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b33c5c434447573b |
|
VISUAL
aHash
|
008f0f272f2fafff |
|
VISUAL
dHash
|
e9185a4b4b4b485a |
|
VISUAL
wHash
|
008f0f21232faffe |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
3d5a4b4b4b4b4852,f469496969492948,41d4d8c4d4d0d0d0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 246 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.