EN ES PT
Back to Stats

Visual Capture

Screenshot of galabet.giris.casa

Detection Info

https://galabet.giris.casa/
Detected Brand
Galabet
Country
International
Confidence
85%
HTTP Status
200
Report ID
a92f0d9f-019…
Analyzed
2026-07-28 11:49

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1D8D2C6A32248A83F13A3D2EAB761177F73E7834DCD1A061A92F5C71807B2D91ED5691C
CONTENT ssdeep
384:IRjKtkD2L7kM07ZAf/ikwfO2z2r0TK0IxE/SeGSw04viLi4gQ5wI:IZWn9wfLfzQeXw04vC5p

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
ed6d531212166d6d
VISUAL aHash
00fbd1fbd9cbdfff
VISUAL dHash
632232132b333c33
VISUAL wHash
00f191ff81818ffd
VISUAL colorHash
072000c0080
VISUAL cropResistant
6332328b2b333c33,008044c4c4448280,6969162969616550,966069a208000000

Code Analysis

Risk Score 53/100
Threat Level MEDIO
⚠️ Phishing Confirmed
🎣 OTP Stealer

🔬 Threat Analysis Report

• Threat: Phishing/Affiliate redirection
• Target: Galabet betting users
• Method: Typosquatting/Domain spoofing
• Exfil: Redirects to malicious betting sites
• Indicators: New domain, obfuscated JS
• Risk: Moderate

🔒 Obfuscation Detected

  • document.write

📊 Risk Score Breakdown

Total Risk Score
75/100

Contributing Factors

Domain Age
Domain is only 1 day old
Content
Affiliate-style gambling redirection site

🔬 Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
Galabet users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer
  • 2 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Galabet
Official Website
https://galabet.com
Fake Service
Betting entry portal

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Traffic Redirection

The site uses legitimate branding to lure users and redirect them to external gambling URLs, potentially tracking clicks or harvesting IP/Device info.

Secondary Method: Typosquatting

Using a generic TLD to mimic legitimate service entry points.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
galabet.giris.casa
Registered
2026-07-27
Registrar
Unknown
Status
active

🤖 AI-Extracted Threat Intelligence

Scan History for galabet.giris.casa

Found 1 other scan for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.