Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T193033F709059A93B02F392E1A7B57F6EB3C5E2C9DA03070426F8C39D8FDBE54E921165 |
|
CONTENT
ssdeep
|
768:sxV8+zdk/sJI7QOnQVQ/pQzQRQvXQloZ1WQ8yeko:cV8+zd6cNqOkuIloZAQ8yk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c74724b8b9b833c5 |
|
VISUAL
aHash
|
ff3020ffffc1ff7f |
|
VISUAL
dHash
|
4d656169eb1bb6c1 |
|
VISUAL
wHash
|
ff20201fff815b60 |
|
VISUAL
colorHash
|
10000000380 |
|
VISUAL
cropResistant
|
8485d3c3e9f474f2,f0da8c4c84268ee4,e0e423c324252717,e9b8625b43763898,fc6323338a8c977a,4d656169eb1bb6c1 |
• Threat: Phishing attempt impersonating Bet365.
• Target: Bet365 users.
• Method: Fake website to steal login credentials.
• Exfil: Likely credential theft via form submission to attacker-controlled server.
• Indicators: Mismatched domain (www.b45077.com vs www.bet365.com), presence of a login form, domain creation date indicating recent registration.
• Risk: HIGH - potential for credential theft.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain