Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C6441AF4936853F496874BD4F9711A0633A610EEFB924688C3B48AD0FBE2ED9D435C61 |
|
CONTENT
ssdeep
|
3072:ozDrTa7jDw/4Q1pSBn1pSBy1pSB61pSBo1pSBafoi2cluAkYc1DI:ya7jDw/47g7/to |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce6131cece61cf30 |
|
VISUAL
aHash
|
00003c3c3c3c0000 |
|
VISUAL
dHash
|
8c3b69696969780c |
|
VISUAL
wHash
|
76893c7d7d7c0c04 |
|
VISUAL
colorHash
|
31001000c00 |
|
VISUAL
cropResistant
|
8e8999e686a68799,8c3b69696969780c |
โข Threat: Potential phishing attempt targeting Bet365 users
โข Target: Users of Bet365, an online gambling platform
โข Method: Displays a website with Bet365 branding with a different URL
โข Exfil: WebSocket URLs are present which are a data exfiltration channel, potentially transmitting user data to attacker-controlled server
โข Indicators: Recent domain, obfuscated Javascript, JavaScript form submission detected, a WebSocket connection to a non-Bet365 domain
โข Risk: MEDIUM - The domain does not correspond to the brand, and the presence of websockets and other indicators are suspicious.
The phishing kit targets Bet365 users by presenting a fake login portal that captures credentials in real-time. It employs an OTP stealer to intercept one-time passwords sent via SMS or authenticator apps, enabling immediate account takeover.
The kit includes a Card Stealer module designed to capture credit/debit card details entered by victims, likely for subsequent fraudulent transactions or resale on darknet markets.
Contains credential harvesting and OTP interception logic, likely with heavy obfuscation to evade analysis.
Pages with identical visual appearance (based on perceptual hash)