Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BD12A47E6104693B4187E2E6B7729B2A3BC28199C7831B0475F9D3989FD6C48CF36642 |
|
CONTENT
ssdeep
|
192:swSuVmPdp8l3Kyjc9mNWKjhJj0j37zjJjUj2Aj6SiJSp9l83H8/B:lYPglXjHWEhFOzFUjp6rJyJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc3333cc8c33ccce |
|
VISUAL
aHash
|
810018183c380000 |
|
VISUAL
dHash
|
030030b270300030 |
|
VISUAL
wHash
|
c38181bdbdbd8181 |
• Threat: Credential harvesting phishing kit
• Target: Netflix users
• Method: Fake landing page stealing email address
• Exfil: Data sent to unknown destination
• Indicators: Free hosting, domain mismatch, Netflix branding
• Risk: HIGH - Immediate email theft
Pages with identical visual appearance (based on perceptual hash)