EN ES PT
Back to Stats

Visual Capture

Screenshot of rollon.bet

Detection Info

https://rollon.bet
Detected Brand
Rollon
Country
International
Confidence
100%
HTTP Status
200
Report ID
5a7ec749-22b…
Analyzed
2026-01-21 13:18
Final URL (after redirects)
https://rollon.bet/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1D7E229B4A230D335B1C24BE8DA642528765FE1DCD7C695B4E388AF51B0D6CE8D9260CF
CONTENT ssdeep
384:4r/aJcuF8ZRhiXkdvNTDhPhLxeAxeDWNW1Tp34PxeeJEmuW3As+cRWbMMd:4r/aJcuQhhPhleMeDGCSPxeeWmHxW

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c6313fdc6c230be8
VISUAL aHash
00666070f0f0f0f0
VISUAL dHash
5cdcdac3a1e4e441
VISUAL wHash
806662f0f8f0fef0
VISUAL colorHash
31601400008
VISUAL cropResistant
5e5e2e8efcf0e049,80c0e6343070f0e4,5cdcdac3a1e4e441

Code Analysis

Risk Score 100/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info
WebSocket C2

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing targeting users of online gambling platforms
• Target: Users of gambling or betting sites
• Method: A fake registration form is used to steal email and password.
• Exfil: Data is likely sent to wss://gambler-work.com/api/ws
• Indicators: Obfuscated JavaScript, Javascript form submission, potentially malicious websocket connection, domain .bet
• Risk: HIGH - Immediate risk of credential theft leading to account compromise

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • base64_strings

📡 API Calls Detected

  • POST
  • GET

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.