Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19451F0FBD145653F524289C7E660BF28F2D2394DED415942D6F329AD07C8DAEE402B0B |
|
CONTENT
ssdeep
|
48:CpDqnm5pwvlB2x6Y56g8PbH7H9/5/bE7E9/56b/7H9/5q/Un:fvlBm6bbbH7H15/bE7E156b/7H15q/Un |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c7bb31c73131c398 |
|
VISUAL
aHash
|
ef3c3c003c7c3000 |
|
VISUAL
dHash
|
496979cc6141401a |
|
VISUAL
wHash
|
ff3c3c307c7c3c00 |
|
VISUAL
colorHash
|
00000000e00 |
|
VISUAL
cropResistant
|
3232b232b6323232,3353131b53131b33,496979cc6141401a |
• Threat: Domain redirect phishing
• Target: Bet365 customers, primarily in Asia
• Method: Redirects users to potentially malicious app download sites or other phishing pages.
• Exfil: Unknown, potential redirection for credential harvesting elsewhere.
• Indicators: Domain Mismatch, document.write obfuscation, possible malicious redirection.
• Risk: HIGH - Potentially dangerous redirection to other malicious sites.
Pages with identical visual appearance (based on perceptual hash)
Found 7 other scans for this domain