Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BED294B02264103AA11B9BDB7F65272B36FBA2FDD8730110D3FC86A49BE5D9DEC12141 |
|
CONTENT
ssdeep
|
384:gVWtqY+SAarN7AyU74CyZUwq/k2o3RYXDFQrcLfVGuxscHYc1RcWxJY6GevxGwBX:gKAarN7AN/ymwx22RYXZQyFYwHO6T5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92b22d2de19296b7 |
|
VISUAL
aHash
|
43047c6c0000607e |
|
VISUAL
dHash
|
969dcd8d926cd4d4 |
|
VISUAL
wHash
|
c7447c7e00247e7e |
|
VISUAL
colorHash
|
38038000000 |
|
VISUAL
cropResistant
|
9c3173f0f03161c7,969dcd8d926cd4d4 |
Fake Chiikawa site positioned to capture victims through SEO tactics, typosquatting, or paid advertising. Serves as entry point for multi-stage attacks including credential theft and malware distribution.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.