Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T184033F709059A93B02F392E1A7B57F6EB3C5E2C9DA03070426F8C39D8FDBE54E921165 |
|
CONTENT
ssdeep
|
768:sxB8+zdn/sJI7QOnQVQ/pQzQRQvXQloZ1WQ8yeko:cB8+zdDcNqOkuIloZAQ8yk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c74724b8b9b833c5 |
|
VISUAL
aHash
|
ff3020ffffc1ff7f |
|
VISUAL
dHash
|
4d656169eb1bb6c1 |
|
VISUAL
wHash
|
ff20201fff815b60 |
|
VISUAL
colorHash
|
10000000380 |
|
VISUAL
cropResistant
|
8485d3c3e9f474f2,f0da8c4c84268ee4,e0e423c324252717,e9b8625b43763898,fc6323338a8c977a,4d656169eb1bb6c1 |
• Threat: Credential harvesting phishing targeting Bet365 users.
• Target: Bet365 users internationally, particularly in regions where online gambling is popular.
• Method: Fake Bet365 login page designed to steal usernames and passwords.
• Exfil: Data is likely sent to a server controlled by the attacker via the /login_action form action.
• Indicators: Domain name mismatch (b45048.com vs bet365.com), presence of a login form, JavaScript form submission detected, and obfuscated JavaScript.
• Risk: HIGH - immediate credential theft likely.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain