Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ACB133B21241DD2E626783E2F732776A23A78289DA46131484FDC3681FD6D5DED3B8C4 |
|
CONTENT
ssdeep
|
96:njYx1ReA77kJLoWKjRzkHo2f9me28kJ2mlornPDRt:jYTRekkloWKj5kHo2f9me2842mlor7Rt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d6c9323469966dd2 |
|
VISUAL
aHash
|
08707c787c026604 |
|
VISUAL
dHash
|
d4c5f1e3e884ccac |
|
VISUAL
wHash
|
68f0fc78fe046e06 |
|
VISUAL
colorHash
|
31601008000 |
|
VISUAL
cropResistant
|
d4c5f1e3e884ccac |
• Threat: Phishing
• Target: Netflix users
• Method: Impersonation and credential harvesting
• Exfil: Unknown, likely to a backend server.
• Indicators: Free hosting, brand logo, input form.
• Risk: High
The attacker aims to steal user credentials by mimicking the Netflix website and prompting for email.
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain