Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A3528373AA27097E721B0EC4E2547334207D6AC1DACE2EA4A5F112B563D6FC86C770E5 |
|
CONTENT
ssdeep
|
192:qFYLq+O9l95IMu4Nln9y9ZhWS9e9WOV9vn4l9m9quL4:K+GP1uAl9SZ32vfIeX4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9ab738b875c23863 |
|
VISUAL
aHash
|
ffffffff00183c00 |
|
VISUAL
dHash
|
2c2e69680ebbe9d9 |
|
VISUAL
wHash
|
ffbfff3c00103c00 |
|
VISUAL
colorHash
|
01006000000 |
|
VISUAL
cropResistant
|
2c2e69680ebbe9d9,9989b99dcdcd8c8d,6e4c4c4c48585858,e88c90b216147271,cc94923a927ae98c,72381c1c2e069392,322323d3e36d6850 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.