Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A112A43E610469374187D1E3B772AB1A3BC282C9DB830B14B1F8D398AFD6D45CB76652 |
|
CONTENT
ssdeep
|
192:rwSulQldp8ZU3K4Pc9mdKjhJj0j37zjJjUj2Aj6SiJSp9l83H8/B:eKlgiNPfEhFOzFUjp6rJyJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cca93304ce737ad8 |
|
VISUAL
aHash
|
0342ddf8b89a4600 |
|
VISUAL
dHash
|
06929133b0348ca4 |
|
VISUAL
wHash
|
034bcff9fc96c600 |
|
VISUAL
colorHash
|
39402008000 |
|
VISUAL
cropResistant
|
680002626a620082,06929133b0348ca4 |
• Amenaza: Phishing
• Objetivo: Usuarios de Netflix
• Método: Suplantación de identidad para robar credenciales
• Exfil: Desconocido, probablemente a una base de datos
• Indicadores: Hosting gratuito, logo de Netflix, formulario solicitando correo electrónico
• Riesgo: Alto
The attacker is using a fake Netflix login page hosted on a free platform to lure users into entering their email address. Once entered, this information is likely saved and used for future malicious attacks.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain