Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CE441AF4536853F496874BE4F9711A0633A610FEFB92468883B48AD0FBE2ED9D435C61 |
|
CONTENT
ssdeep
|
3072:MBDZTa7jDw/4Q1pSBn1pSBy1pSB61pSBo1pSBafoi2cluAkYc1DI:247jDw/47g7/to |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce6131ce8e2dcf30 |
|
VISUAL
aHash
|
00003c3c3c3c0000 |
|
VISUAL
dHash
|
aadce86969697904 |
|
VISUAL
wHash
|
007e7e7f7f7c0400 |
|
VISUAL
colorHash
|
39001000c00 |
|
VISUAL
cropResistant
|
8e8999e686a68799,aadce86969697904 |
• Threat: Phishing
• Target: bet365 users
• Method: Domain impersonation and branding mimicry. Likely designed to steal user credentials or financial information.
• Exfil: Detected WebSocket URLs, indicating potential data exfiltration.
• Indicators: Domain age, domain mismatch, obfuscation, JS form submission.
• Risk: HIGH
The attackers are trying to trick users into entering their bet365 credentials on a fake login page that is almost identical to the real website, making it highly effective at impersonation.
WebSocket URLs have been detected, indicating this malicious site could be designed to covertly transmit collected data to the attacker, or receive commands and execute them without user interaction. This can potentially be used to extract sensitive information.
Pages with identical visual appearance (based on perceptual hash)