Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E5E2E836A11C693F931709C8B0A16F6BF157571FEA5268806BAC7BF01FD6CB1D90A10B |
|
CONTENT
ssdeep
|
768:uEpISgGK2u+8y/RsMSwKMnaRARn8+n8gA:uEp3KTS9B8+nLA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e8bf17a4e189a05b |
|
VISUAL
aHash
|
d383f9f9e1f30000 |
|
VISUAL
dHash
|
266e119387a7f3c0 |
|
VISUAL
wHash
|
f7a3fde1f1e30000 |
|
VISUAL
colorHash
|
39600010000 |
|
VISUAL
cropResistant
|
266e119387a7f3c0 |
• Ameaça: Phishing
• Alvo: Usuários do Netflix
• Método: Falsificação de domínio e coleta de credenciais
• Exfil: Provavelmente para um banco de dados controlado pelo atacante. A ofuscação sugere tentativas de evitar a detecção.
• Indicadores: Incompatibilidade de domínio, presença de formulário, código ofuscado.
• Risco: Alto
The attacker is using a fake login page that mimics Netflix to trick users into entering their credentials. The collected data is likely saved on the server.
The attacker is using a domain that is unrelated to Netflix to host a copy of the official website.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain