Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18072B77180941A3B4243E5D0EBA56B2BE2D3C289CE920D5553F4D39853EBEF4DE5ACE0 |
|
CONTENT
ssdeep
|
192:GA4owjBe+FJuebPOEsBLilBIc5/HVb7I5iAq:GHjBl3uebPz2Lilp/NIDq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b63146876704f76 |
|
VISUAL
aHash
|
00df390f89190f1f |
|
VISUAL
dHash
|
be1a7b5b3b3b3b38 |
|
VISUAL
wHash
|
00df3f0f89190f1f |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
9a7b7b1b3b3b3b38,e4e1c26450622607,00a4232caca98038,878682ac13939326,40167169d628a1a2,145b1e4c4f4ecf0b,262949ca23515113,b04d617186696915,4b34f42a82b42945 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.