EN ES PT
Back to Stats

Visual Capture

Screenshot of 92493.my

Detection Info

https://92493.my/
Detected Brand
Unknown (Gambling site)
Country
International
Confidence
100%
HTTP Status
200
Report ID
a57961ce-820…
Analyzed
2026-02-27 16:06

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1FF924672C141BCA7C07246C1F5359B55218682CAEB430EA093FC0B5EFA9ADB5C87F5E9
CONTENT ssdeep
192:BfyfWxeMePxI2vxo1Q1rgILEWIPIMQ61C:gMGhgIXIPIv

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
98d9673298cd7236
VISUAL aHash
1800181818000000
VISUAL dHash
122ab2b2b0093620
VISUAL wHash
183c3c3c3c3c1038
VISUAL colorHash
38600018000
VISUAL cropResistant
2216963622303232,122ab2b2b0093620

Code Analysis

Risk Score 68/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Unsuspecting users
• Method: Deception, enticing with bonuses
• Exfil: Unclear from this screenshot, likely credential harvesting or potentially financial data.
• Indicators: Suspicious domain, JavaScript obfuscation, forms, bonuses.
• Risk: HIGH

🔒 Obfuscation Detected

  • fromCharCode

📡 API Calls Detected

  • /api/captcha/sms-otp
  • /api/ban-ips/is-banned
  • /api/captcha
  • POST
  • /api/members/create-member-anonymous
  • GET

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Suspicious Domain
The domain is not associated with any known legitimate brand. Domain age is a factor, but not primary.
JavaScript Obfuscation
JavaScript obfuscation is a common technique to hide malicious code from detection.
Incentives/Bonuses
Offering bonuses and rewards is a common tactic to lure users into providing information.
Form Submission
Form submissions increase the probability of malicious intent

🔬 Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
Unknown (Gambling site) users (International)
Attack Method
credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer
  • 4 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
澳门新葡京
Fake Service
Gambling website.

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The site likely attempts to harvest credentials (username/password) through the registration process or any other form.

Secondary Method: Malware distribution via drive-by downloads or redirects.

The site could be used to install malware if the user interacts with the elements.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
92493.my
Registered
2024-01-24
Registrar
Unknown
Status
active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.