Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T191F22F70A156AA7B02F392F1AB756B6FB3D1E2C8D943470426F8835D9FCBE84ED21051 |
|
CONTENT
ssdeep
|
384:ddgUMxl558g+VWM7zICygUyD084mR8m9Rdlz/YBN5BnA89A:ddgZ8g+VZ731WQ8yRKLF9A |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ca1621738fd68ecc |
|
VISUAL
aHash
|
00003c3c3c38c0fb |
|
VISUAL
dHash
|
4c9b6169696b92a2 |
|
VISUAL
wHash
|
00003c3c3cfdfafb |
|
VISUAL
colorHash
|
01000000e00 |
|
VISUAL
cropResistant
|
cc82155586664c46,46c686a6b6b6a626,3e3e7a3a98991ab3,4c9b6169696b92a2 |
• Threat: Credential harvesting phishing targeting bet365 users.
• Target: bet365 users.
• Method: Fake login page designed to steal usernames and passwords.
• Exfil: Data likely exfiltrated to a malicious server via /login_action. The use of eval, fromCharCode, unescape suggests obfuscation to hide the exfiltration method.
• Indicators: Domain name does not match official domain, login form present, obfuscated javascript.
• Risk: HIGH - Real-time credential theft.
Pages with identical visual appearance (based on perceptual hash)
Found 6 other scans for this domain