Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11534C871630555290B3BC6F0E53A13A7A2CB944FB6636070AE6DE7A739C3F64EA0F114 |
|
CONTENT
ssdeep
|
6144:boKaqq6iDyk2SsmOkaIXClvmXHUwmrAMcmcoOsmGoMvmLo9smQbEMmRojEmDo+Da:yKX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b1cccece31ce3131 |
|
VISUAL
aHash
|
ffcfc7c7c7cfefc7 |
|
VISUAL
dHash
|
b69a9a9a9a9a9a98 |
|
VISUAL
wHash
|
c3c34343c7c7c746 |
|
VISUAL
colorHash
|
0e001010002 |
|
VISUAL
cropResistant
|
b69a9a9a9a9a9a98,05f10df0b10d1101,1111812101010101 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6604 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.