Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F153C7AC51440032921F1C97E82D764DE19FC2098626ADA4AFB472C77FC5E954B0AFFE |
|
CONTENT
ssdeep
|
768:Hd1I3liyvSUDB5sH1VJfubGKgB8Tnbyz47U/CDvFFexdQo/QqQf1++Ok27UU7UEd:yG1Lj/yAo27p7J7v7Q7vdpY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bd9560e842eb4e9a |
|
VISUAL
aHash
|
a39f9fff9fdbcf00 |
|
VISUAL
dHash
|
4f3e3a583c233b8d |
|
VISUAL
wHash
|
010f8fff8fc1cf00 |
|
VISUAL
colorHash
|
0e207000000 |
|
VISUAL
cropResistant
|
6f16385a5c3a233b,0000000000000000,54557be1e5211011,23232b3b1b2dc785 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 381 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.