Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1045399726085ECB305A39AD0A5F4631E63A9D75BCE4347C3A3F8E79C6BDAD84EC12510 |
|
CONTENT
ssdeep
|
768:G0X1cJRSwUjroPLDCvnc/Fcbg+bV5F2u5v/2h6zad402w:zX1cJRSwUjroK5h2hoFHw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f9295287d2a978a9 |
|
VISUAL
aHash
|
0000c3dfffffffff |
|
VISUAL
dHash
|
c10f1b1340686b28 |
|
VISUAL
wHash
|
00008181ffffffac |
|
VISUAL
colorHash
|
06000000180 |
|
VISUAL
cropResistant
|
0429492929490104,0f1b134068686b28,209cd2d2cc601020,1f9e8e961b3b3b1f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 75 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.