Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E5E2E836A11C693F931709C8B0A16F6BF157571FEA5268806BAC7BF01FD6CB1D90A10B |
|
CONTENT
ssdeep
|
768:uEpISgGK2u+8y/RsMSwKMnaRARn8+n8gA:uEp3KTS9B8+nLA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e8bf17a4e189a05b |
|
VISUAL
aHash
|
d383f9f9e1f30000 |
|
VISUAL
dHash
|
266e119387a7f3c0 |
|
VISUAL
wHash
|
f7a3fde1f1e30000 |
|
VISUAL
colorHash
|
39600010000 |
|
VISUAL
cropResistant
|
266e119387a7f3c0 |
• Threat: Phishing
• Target: Netflix users
• Method: Domain spoofing and credential harvesting
• Exfil: Likely to a database controlled by the attacker. Obfuscation suggests attempts to avoid detection.
• Indicators: Domain mismatch, form presence, obfuscated code.
• Risk: High
The attacker is using a fake login page that mimics Netflix to trick users into entering their credentials. The collected data is likely saved on the server.
The attacker is using a domain that is unrelated to Netflix to host a copy of the official website.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain