EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

https://desbet.top/
Detected Brand
Unknown
Country
International
Confidence
100%
HTTP Status
200
Report ID
66e863ab-0ce…
Analyzed
2026-02-19 17:11

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1A0E239B49230E335B1C247E8DA6429687A5FE1DCD7C695B0E388AF51B0D6CE8D5150CF
CONTENT ssdeep
768:4r/aMJgueHC9enHhhPhleMeDGCSPxeeWmHdW:SGpxFWwW

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c3073cf2781c786b
VISUAL aHash
0066203860e67610
VISUAL dHash
4c4c4ac14bc8acb1
VISUAL wHash
80263e38e8fe7f50
VISUAL colorHash
30000600018
VISUAL cropResistant
f057debbb2d4e972,4c4c4ac14bc8acb1

Code Analysis

Risk Score 100/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info
WebSocket C2

🔬 Threat Analysis Report

• Threat: Impersonation phishing
• Target: Users seeking to register with an "official casino"
• Method: Deception using Elon Musk's image
• Exfil: Credentials via form submission and WebSocket connection.
• Indicators: Recent domain, Musk impersonation, registration form
• Risk: High

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • unicode_escape
  • base64_strings

📡 API Calls Detected

  • POST
  • GET

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Recent Domain
The domain is very recent (less than 30 days old), a common characteristic of phishing sites.
Impersonation
The website heavily relies on the image of Elon Musk, a clear sign of an attempt to deceive users.
Form with Credentials
The registration form is designed to collect user credentials such as email and password.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
General public
Attack Method
Brand impersonation + real-time WebSocket exfiltration + obfuscated JavaScript
Exfiltration Channel
WebSocket (1 endpoints)
Risk Assessment
CRITICAL - Automated credential harvesting with WebSocket (1 endpoints)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 169 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Elon Musk
Fake Service
Official Casino

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The site aims to collect user credentials via a registration form, likely to gain access to accounts or perform fraudulent activities. It uses social engineering, by leveraging the Elon Musk's image, to trick users.

Secondary Method: Malicious Script Execution

The presence of obfuscated Javascript indicates possible execution of malicious code, like keyloggers, or potentially redirecting to another phishing page.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
desbet.top
Registered
2024-02-10
Registrar
Namecheap
Status
Active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.