EN ES PT
Back to Stats

Visual Capture

Screenshot of bet73022.com

Detection Info

https://bet73022.com/
Detected Brand
Bet365
Country
International
Confidence
100%
HTTP Status
200
Report ID
9aacd3ff-bd3…
Analyzed
2026-01-01 08:27
Final URL (after redirects)
https://bet73022.com/#

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T191F22F70A156AA7B02F392F1AB756B6FB3D1E2C8D943470426F8835D9FCBE84ED21051
CONTENT ssdeep
384:ddgUMxl558g+VWM7zICygUyD084mR8m9Rdlz/YBN5BnA89A:ddgZ8g+VZ731WQ8yRKLF9A

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
ca1621738fd68ecc
VISUAL aHash
00003c3c3c38c0fb
VISUAL dHash
4c9b6169696b92a2
VISUAL wHash
00003c3c3cfdfafb
VISUAL colorHash
01000000e00
VISUAL cropResistant
cc82155586664c46,46c686a6b6b6a626,3e3e7a3a98991ab3,4c9b6169696b92a2

Code Analysis

Risk Score 95/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing targeting bet365 users.
• Target: bet365 users.
• Method: Fake login page designed to steal usernames and passwords.
• Exfil: Data likely exfiltrated to a malicious server via /login_action. The use of eval, fromCharCode, unescape suggests obfuscation to hide the exfiltration method.
• Indicators: Domain name does not match official domain, login form present, obfuscated javascript.
• Risk: HIGH - Real-time credential theft.

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • eval
  • fromCharCode
  • unescape
  • document.write
  • hex_escape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • #normalLogin
  • //3f38sfb.segrft.com/plus/css/custom/login_modal_custom.css?ver=1726650059?v=1767256022
  • //3f38sfb.segrft.com/plus/css/unite/login_modal_unite.css?ver=1738950076?v=1767256022
  • //3f38sfb.segrft.com/plus/css/unite/login_unite.css?ver=1614680239
  • //3f38sfb.segrft.com/plus/js/custom/login.js?ver=1597629260
  • /login_action
  • //3f38sfb.segrft.com/plus/js/custom/login_custom.js?ver=1598008226
  • //3f38sfb.segrft.com/plus/css/custom/login_custom.css?ver=1663905027

📡 API Calls Detected

  • https://1hh1n2l4.00oiiamw.com/chatwindow.aspx?siteId=60001038&planId=ce938562-5837-4db2-9aee-934d6d6e8549
  • /mbuhx0as4kui
  • /prizedraw/default
  • /forgot
  • /loadGame/

📤 Form Action Targets

  • /login_action

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.