Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15231AC3180C48CAF0692C7E8CA36761BF2C6835CDB136B0585F947AE2B4AE66CC07C45 |
|
CONTENT
ssdeep
|
24:hPCcHIdT/u4F0lC9HXHJbqkrHXHJaV662DQCa5PUR/2DQJY92t6dT:hHgu4F0lIbLaV666Qc6QJSHdT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8dad624a3c879d0f |
|
VISUAL
aHash
|
10183e1a18183800 |
|
VISUAL
dHash
|
a1f2f23232f0f0cc |
|
VISUAL
wHash
|
187e3f3f187c7c00 |
|
VISUAL
colorHash
|
39600008001 |
|
VISUAL
cropResistant
|
8c96868eaaaa869e,a1f2f23232f0f0cc |
• Threat: Phishing
• Target: Users interested in gambling or Atletico Madrid
• Method: Impersonation and promotional claims
• Exfil: Unknown (JS obfuscation indicates potential data theft or redirect)
• Indicators: Domain mismatch, use of brand logos, promotional content, obfuscated JS
• Risk: High
The site uses the K8 and Atletico Madrid brands to impersonate a legitimate service, luring users to visit the site. The domain name is not related to either of the brands, a common phishing tactic.
The obfuscated Javascript has the potential to redirect the user to a different malicious website after a short wait, to steal credentials.
Pages with identical visual appearance (based on perceptual hash)
Found 3 other scans for this domain