Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T182032070A05AA93B01F3A2F66B753B1EB3C5D28AD903470426F8D39E4FDBE90ED21155 |
|
CONTENT
ssdeep
|
768:dqk8g+VeHYLOE+ZUXnXpUTPbsPg9oZ1WQ8yRK:ok8g+Ve4LZUoZAQ8yM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8d3937647298569 |
|
VISUAL
aHash
|
ffff7f0081f7013c |
|
VISUAL
dHash
|
4c19d23327263be9 |
|
VISUAL
wHash
|
3cff7a0081df013e |
|
VISUAL
colorHash
|
08001000380 |
|
VISUAL
cropResistant
|
0c00080880e2f8fc,24d2c0b2b2c0d222,6d296364f132a88d,f8e4c30a23d376b4,aee0e8f0e8c89625,4c19d23327263be9 |
⢠Threat: Credential harvesting phishing attack targeting Bet365 users.
⢠Target: Bet365 users internationally.
⢠Method: Fake login page to steal usernames and passwords.
⢠Exfil: Data likely sent to a malicious server, no specific target extracted from the provided information.
⢠Indicators: Domain mismatch, obfuscated Javascript, login form, and brand impersonation.
⢠Risk: CRITICAL - Immediate credential theft.
Pages with identical visual appearance (based on perceptual hash)