Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10723A9726045DC7305A3B9D1B5B9670E729AC30BCE0307C7A3F89B9C6BDAE85ED22511 |
|
CONTENT
ssdeep
|
384:uvvOdoumuwcJ9DWU793XiC2+r8nY0cXXMwU5DiKN3qfd4bdf2ZQF:uO8cXDWUZ3Lo3S8wUQKh8d4bR2w |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9625542d56a9dea9 |
|
VISUAL
aHash
|
0000fffffffffffc |
|
VISUAL
dHash
|
d44c60584868da34 |
|
VISUAL
wHash
|
0000aeaeaebe9f8c |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
0000222323000000,687878486878da34,048b94d4d484ab00 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 32 techniques to evade detection by security scanners and make reverse engineering more difficult.
Drainer supports multiple blockchain networks and checks for high-value tokens on each chain before executing drain operations.