Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1355100BBD144653F524289C7E660BF24F2D2394DEA516542D6F229AD07C8DADE402B07 |
|
CONTENT
ssdeep
|
48:CpDqnm5pwvlB2x6a5Qg8PbX7H9/5/bK7E9/56bp7H9/5q/Un:fvlBm6jbbX7H15/bK7E156bp7H15q/Un |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c7bb31c73131c398 |
|
VISUAL
aHash
|
ef3c3c003c7c3000 |
|
VISUAL
dHash
|
496979cc6141401a |
|
VISUAL
wHash
|
ff3c3c307c7c3c00 |
|
VISUAL
colorHash
|
00000000e00 |
|
VISUAL
cropResistant
|
3232b232b6323232,3353131b53131b33,496979cc6141401a |
• Amenaza: Sitio de phishing que suplanta a bet365
• Objetivo: Usuarios de bet365
• Método: Página falsa de inicio de sesión o verificación
• Exfil: Posible exfiltración de datos a través de JavaScript ofuscado
• Indicadores: Dominio no coincidente, JS ofuscado, URL sospechosa
• Riesgo: ALTO - Posible robo de credenciales
Pages with identical visual appearance (based on perceptual hash)
Found 7 other scans for this domain