Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T134E210709116AA7B02B392E0A7752B6EB3C5E2C8D903071416F8C7ADDFCFF94E925191 |
|
CONTENT
ssdeep
|
384:d3jpr8g+VkBeGUe5CygUyD084mR8m9RdlzK:d358g+VGB5E1WQ8yRK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
868692f1f1f1a68e |
|
VISUAL
aHash
|
ff34306000000000 |
|
VISUAL
dHash
|
5c6565d280000000 |
|
VISUAL
wHash
|
ff1410ffc0c0c0c0 |
|
VISUAL
colorHash
|
0f000000e00 |
|
VISUAL
cropResistant
|
5c6565d280000000 |
• Threat: Credential harvesting phishing kit targeting Bet365 users.
• Target: Bet365 customers internationally.
• Method: Fake login page designed to steal usernames and passwords.
• Exfil: Data is likely sent to a malicious server controlled by the attacker. (Form action: /login_action)
• Indicators: Domain name mismatch (bet73022.com vs bet365.com), obfuscated JavaScript, and the presence of a login form.
• Risk: HIGH - Immediate credential theft.
Pages with identical visual appearance (based on perceptual hash)
Found 6 other scans for this domain