Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17C0341709059AA3B02F392E167B56F6EB3C5E2C9D9030B0526FCC39D8FDEE54E921161 |
|
CONTENT
ssdeep
|
768:sx88+zdt/so/zQ+QTQkQo9VQLoZ1WQ8yeko:c88+zdnklE3lLoZAQ8yk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c64709b8b0b93dc7 |
|
VISUAL
aHash
|
ff3020ffff83ff7f |
|
VISUAL
dHash
|
4d6561c8cc276bf8 |
|
VISUAL
wHash
|
3420206fff813f3e |
|
VISUAL
colorHash
|
080000003c0 |
|
VISUAL
cropResistant
|
8485d3c3e9f474f2,92b32aaa62b8ace2,8f16744d4ec66e9a,a48123278f972b39,c8d2838d35b39369,4d6561c8cc276bf8 |
• Threat: Credential harvesting phishing targeting Bet365 users
• Target: Bet365 users
• Method: Fake login page designed to steal usernames and passwords.
• Exfil: Potentially exfiltrates data through /login_action form or custom javascript.
• Indicators: Domain mismatch (www.b45060.com vs bet365.com), presence of login form, and JavaScript form submission with obfuscation.
• Risk: HIGH - Potential for immediate credential theft and account compromise.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain