Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EE51433B7044605B0693A3B53F21DB5B3A87815A8F260F1520B5DB9F6FD6E09CC462DE |
|
CONTENT
ssdeep
|
48:nX5NJhIJafr9m9pKTfS2e5Sw099gjw4myuKWgXw4YHzwM0XlBcuB:n+aD9m9pKTfSf5RK9gjFESSQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d3972972c66d3990 |
|
VISUAL
aHash
|
a32c7e7cfec4e000 |
|
VISUAL
dHash
|
4a48bae0ec198bc2 |
|
VISUAL
wHash
|
a2ac7e7efec4e000 |
|
VISUAL
colorHash
|
32600008040 |
|
VISUAL
cropResistant
|
c5c000e060c000c8,4a48bae0ec198bc2 |
• Threat: Credential harvesting phishing attack
• Target: Netflix users
• Method: Fake Netflix login page to steal email addresses
• Exfil: Likely sending data to an attacker-controlled server (details unknown)
• Indicators: Free hosting on Github Pages, impersonating Netflix brand, input field for email.
• Risk: HIGH - Potential credential theft and account compromise
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain