Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ACA253A051059D3741A393D27673472B32F0C205DB07066953FD93A99BEECB8ED2F962 |
|
CONTENT
ssdeep
|
192:A4UR+B488HRT26lOq+KBaIYqk961b8AtOQGHzwc9dGRbOj/:A4UR+4HRTdlOqHaIYq91/rGTwc9dDz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc99336699996666 |
|
VISUAL
aHash
|
0000181818180000 |
|
VISUAL
dHash
|
0000303030300000 |
|
VISUAL
wHash
|
00003c3c18180000 |
|
VISUAL
colorHash
|
38000000007 |
|
VISUAL
cropResistant
|
0000303030300000 |
• Threat: Phishing
• Target: Netflix users
• Method: Impersonation via loading screen.
• Exfil: Unknown (likely credentials or malware download)
• Indicators: Free hosting, Netflix logo, loading screen
• Risk: High
The attacker likely intends to steal Netflix login credentials. They use a familiar visual element (the loading screen) to entice users and then redirect them to a fake login form or execute malicious script.
The loading screen could be used as a pretense to download malware on the device.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain