Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9A110A61241DE2E5177C3E2B332377A23A68289DA46130485FED3681BD6D5DED3B8C4 |
|
CONTENT
ssdeep
|
96:npY81ReAt7kJLoWKjRzkHo2f9me281JfbQorn5:pYwReykloWKj5kHo2f9me28bfbQor5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
964db62469966dd2 |
|
VISUAL
aHash
|
003c7e0800066e0e |
|
VISUAL
dHash
|
06c4d03801c4cccc |
|
VISUAL
wHash
|
02007e3cff0e7e4e |
|
VISUAL
colorHash
|
38600018000 |
|
VISUAL
cropResistant
|
e4f43230e4a1a1e0,06c4d03801c4cccc |
• Amenaza: Phishing
• Objetivo: Usuarios de Netflix
• Método: Recopilación de credenciales
• Exfil: Desconocido, probablemente al atacante
• Indicadores: Alojamiento gratuito, suplantación de marca, entrada de correo electrónico.
• Riesgo: Alto
The attacker aims to steal user credentials (email and password) by creating a fake login form that looks like Netflix. Victims enter their details, which are then sent to the attacker.
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain