Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156C3BF306848CC3701FBA2E66371771EA282D357C6174B5427F2D39E9BE6EA4ED2116C |
|
CONTENT
ssdeep
|
1536:cL8+zd5ORIbwtydL1sCPUdnsNJ8lePpTA8wIwYm3bltLiaPy7MiHZzv3AQ8yk:sQltWaPy7JHZzvQb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e1b2933c4b2ec565 |
|
VISUAL
aHash
|
26ff7e00817e017e |
|
VISUAL
dHash
|
4d19d40b33f627c8 |
|
VISUAL
wHash
|
24ff7e0081ff007e |
|
VISUAL
colorHash
|
00001000380 |
|
VISUAL
cropResistant
|
0c04000880e3f0fd,22d4c0b2b2c0d202,0b0b0f8f9c78c000,f8ce869616ea9ac0,adcdca9c8db187af,73735173cb5b330b,c3c454729dd7537a,7a6b933b2b5796ac,d8d818089a9adeb5,93d8e7dc5e2aaaca,4d19d40b33f627c8 |
• Threat: Potentially unwanted program (PUP) due to the non-standard domain
• Target: Users of bet365, particularly those accessing the site from regions where the main domain is restricted
• Method: Redirects users to a secondary domain for gaming and betting services
• Exfil: Unknown, likely user credentials or game activity data to bet365 servers (if legitimate)
• Indicators: Non-standard domain (b45030.com), presence of login form
• Risk: LOW - Requires further investigation to confirm legitimacy but presents a potential security risk if it is not properly affiliated with bet365
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain