Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10B230B30C55AE93705F382E1A774AB5FB395E289DC13870526FA832EAFCBE94EC51051 |
|
CONTENT
ssdeep
|
768:rTc8g+V3LveDA9oPhbD55/i5/8v+ZYScRG3SPKNyVUrwE9nU/tVovfKfVp6zQxaS:Hc8g+V7veDA9oPhbD55/i5/8v+ZYScRd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce8c92b1b1b3a38e |
|
VISUAL
aHash
|
ff183000183c3c3c |
|
VISUAL
dHash
|
5c75654270717171 |
|
VISUAL
wHash
|
ff1c30383c3c3c3c |
|
VISUAL
colorHash
|
0f000008e00 |
|
VISUAL
cropResistant
|
dadadadefcf2b2b2,5c75654270717171 |
• Threat: Credential harvesting phishing attack
• Target: Bet365 users
• Method: Fake login form stealing usernames and passwords
• Exfil: Unknown data exfiltration point (likely a custom API or database)
• Indicators: Domain mismatch (bet83080.com vs. bet365.com), login form on a non-official domain.
• Risk: HIGH - Immediate credential theft leading to account compromise
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain