Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13E13C772A040353A11B383D1F6297F4DB1EA404FCB6605E1F6FEC26E5BD2E60A87115E |
|
CONTENT
ssdeep
|
384:GbO5zMTK8F0RTwnjd/kzQJJvnT8vkV/VHshVjV0VqynGKWcT7U+aON1KmtiXFVvT:1BRTAdIQJlkc3UvbQsVvdN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc4369136553696b |
|
VISUAL
aHash
|
00c3c3ffffffffc3 |
|
VISUAL
dHash
|
d02733202f303237 |
|
VISUAL
wHash
|
000081ffcf9fdf83 |
|
VISUAL
colorHash
|
06001208080 |
|
VISUAL
cropResistant
|
3733202b2f303237,4dd2d2d920089011,0000343032100800,40e0646177d6d6b2 |
• Threat: Phishing/Credential Harvesting
• Target: Rainbet Casino users
• Method: SEO-bait promo code page with obfuscated scripts
• Exfil: JavaScript-based submission to external host
• Indicators: Domain mismatch, obfuscation, suspicious redirects
• Risk: High
Uses deceptive content to route users through obfuscated links for tracking or malicious payload delivery.
Mimics legitimate branding to deceive users into interacting with fraudulent promo schemes.