Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9A110A61241DE2E5177C3E2B332377A23A68289DA46130485FED3681BD6D5DED3B8C4 |
|
CONTENT
ssdeep
|
96:npY81ReAt7kJLoWKjRzkHo2f9me281JfbQorn5:pYwReykloWKj5kHo2f9me28bfbQor5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
964db62469966dd2 |
|
VISUAL
aHash
|
003c7e0800066e0e |
|
VISUAL
dHash
|
06c4d03801c4cccc |
|
VISUAL
wHash
|
02007e3cff0e7e4e |
|
VISUAL
colorHash
|
38600018000 |
|
VISUAL
cropResistant
|
e4f43230e4a1a1e0,06c4d03801c4cccc |
• Ameaça: Phishing
• Alvo: Usuários da Netflix
• Método: Coleta de credenciais
• Exfil: Desconhecido, provavelmente para o atacante
• Indicadores: Hospedagem gratuita, personificação da marca, entrada de e-mail.
• Risco: Alto
The attacker aims to steal user credentials (email and password) by creating a fake login form that looks like Netflix. Victims enter their details, which are then sent to the attacker.
Pages with identical visual appearance (based on perceptual hash)
Found 5 other scans for this domain