Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T105E153661241DD2A1567C2E2B332372B73A68288EB47130095FED3681FD6E4DED3B9C4 |
|
CONTENT
ssdeep
|
192:eNR8kloWKj5kHo2f9me/wFeD6rwOtJf1bxTCD:eNRHYwD34UD6s6NtT0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d6c9323469966dd2 |
|
VISUAL
aHash
|
087c7c387c026604 |
|
VISUAL
dHash
|
50c5f1e3e884cccc |
|
VISUAL
wHash
|
28f0fe78fe046e06 |
|
VISUAL
colorHash
|
31601008000 |
|
VISUAL
cropResistant
|
e4f43230e4a1a1e0,50c5f1e3e884cccc |
• Amenaza: Phishing
• Objetivo: Usuarios de Netflix
• Método: Suplantación de identidad a través de alojamiento gratuito
• Exfil: Probablemente credenciales/información de pago
• Indicadores: Alojamiento gratuito, logotipo de la marca, CTAs
• Riesgo: Alto
The attacker likely aims to collect the victim's Netflix login credentials through a fake login page or form, disguised as the real Netflix site. This is a common phishing technique.
The attacker may inject malicious JavaScript code into the phishing page to redirect the user to a malware download or credential harvesting form.
Pages with identical visual appearance (based on perceptual hash)