Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10AB131A21245DE2E516782E2F372377A23A68289CA46130484FDD3681FE6D5DED3F9C4 |
|
CONTENT
ssdeep
|
96:np+RLAp7kJLo2f9meRzkHo2f9me281JfbQornGBu:p+RLaklo2f9me5kHo2f9me28bfbQor5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d2e9366d922dca86 |
|
VISUAL
aHash
|
62203c387c780666 |
|
VISUAL
dHash
|
d4d06161e8d0cccc |
|
VISUAL
wHash
|
7a603c787c7e0666 |
|
VISUAL
colorHash
|
31401008000 |
|
VISUAL
cropResistant
|
e4f43230e4a1a1e0,d4d06161e8d0cccc |
• Amenaza: Phishing
• Objetivo: Usuarios de Netflix
• Método: Suplantación de identidad a través de una página de inicio de sesión falsa
• Exfil: Dirección de correo electrónico
• Indicadores: Alojamiento gratuito, logotipo de Netflix, formulario
• Riesgo: Alto
The attacker aims to steal user credentials (email address in this case) by creating a fake login page that mimics the official Netflix website.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain