Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1014111F2D249A93221528AD6FF74B738F6D2014EF9411253C6F116FD03C9E79D042A47 |
|
CONTENT
ssdeep
|
24:kmspWxqnINXwbg35xuOala5Cx65z5Pm8uOKnFWEK1hxCFbjv+OhoQQC+bjvyhoQW:CpWxqnm5pwvlFx6rQ07m7roT7aoH7ro6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cfb331c73131c698 |
|
VISUAL
aHash
|
ef3c3c003c7c3000 |
|
VISUAL
dHash
|
4969792af165600a |
|
VISUAL
wHash
|
ff3c3c307c7c3c00 |
• Threat: Brand impersonation phishing
• Target: Bet365 customers
• Method: Redirects users to a different domain and promotes a new website.
• Exfil: Unknown, likely to harvest credentials or redirect to malicious content.
• Indicators: Domain mismatch, message about domain expiring, promoting new website.
• Risk: HIGH - Potential for credential theft or malware infection.
Pages with identical visual appearance (based on perceptual hash)
Found 4 other scans for this domain