Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9A110A61241DE2E5177C3E2B332377A23A68289DA46130485FED3681BD6D5DED3B8C4 |
|
CONTENT
ssdeep
|
96:npY81ReAt7kJLoWKjRzkHo2f9me281JfbQorn5:pYwReykloWKj5kHo2f9me28bfbQor5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c39f24643ec99ec4 |
|
VISUAL
aHash
|
007c7e1800007006 |
|
VISUAL
dHash
|
06c4d03800c8c2cc |
|
VISUAL
wHash
|
06007e3cff067a6e |
• Threat: Credential harvesting phishing kit
• Target: Netflix users
• Method: Fake landing page prompting users to enter their email to 'get started'.
• Exfil: Email address is likely being collected and stored by the attacker. The specific exfiltration method is unknown, but likely sent to a database or email address controlled by the attacker.
• Indicators: Free hosting, Netflix-like design, requests email address
• Risk: HIGH - Email addresses are being collected for potential phishing attacks and credential stuffing.
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain