Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T162F2F66A4241257D10134EF6F5A1B7A9D056C68FC6938E67F2ED83E20BC7C52DA7138C |
|
CONTENT
ssdeep
|
768:DTL5BEoueyk+v/KJxwh6peyk+u/KJWwhHD6bkx+5/KJtxwhMxokN/qXho:8odyk+46hvykl4zhWbkE54t6hMNqXho |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec6c93c3cd919338 |
|
VISUAL
aHash
|
ff91818191ffdfff |
|
VISUAL
dHash
|
2223333727133827 |
|
VISUAL
wHash
|
ff81818080f1cfef |
|
VISUAL
colorHash
|
07c00008000 |
|
VISUAL
cropResistant
|
2223333727133827 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 239 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.