Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A33382725444243F132753C9F122771EF1E3930ECA9708A9B3F98B974BE3D94991A86B |
|
CONTENT
ssdeep
|
1536:46lA62FvhtQIE65350PcQ2LkwfdD81quTa2NM7Kb0VOU3j9gOsr5Zdl49h2SURb3:zovLmZTa2NDfJVFeWyolfwHD1g4cXKTi |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e0709f2dc23fb2e0 |
|
VISUAL
aHash
|
80004464e003007f |
|
VISUAL
dHash
|
440c8c848c8743cc |
|
VISUAL
wHash
|
f70666766007037f |
|
VISUAL
colorHash
|
38000006000 |
|
VISUAL
cropResistant
|
440c8c848c8743cc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 813 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.