Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17912B43E610469374187D1E2B772AB1A3BC282C8DB830B04B0F8D398AFD6C45CB76642 |
|
CONTENT
ssdeep
|
192:swSu9Qlep8ZU3K4Pc9mdKjhJj0j37zjJjUj2Aj6SiJSpTl83H8/B:lSlbiNPfEhFOzFUjp6rJQJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dca93304ce733ad8 |
|
VISUAL
aHash
|
0342ddf8b89a4600 |
|
VISUAL
dHash
|
06929133b0348ca4 |
|
VISUAL
wHash
|
034bcff9fc96c600 |
• Threat: Email harvesting phishing targeting Netflix users.
• Target: Individuals wanting to start/restart a Netflix membership
• Method: Fake Netflix landing page asking for email address to start a membership.
• Exfil: Email address is likely sent to attacker-controlled server.
• Indicators: Free hosting on GitHub Pages, brand impersonation, domain mismatch.
• Risk: MEDIUM - Potential for credential theft and spam.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain