Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T129F23070945AAA3702F3A2E57B743B5EB3C5E289D903070426F8D39E4FDBE94ED21161 |
|
CONTENT
ssdeep
|
384:wT3Jbc+VWfzKYvwKQoyLQ5/kSPoWCygUyD084mR8m9Q8lzK:wT9c+V0ztvwKQoyLQ5/kSPoZ1WQ8yVK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e992966f6729c134 |
|
VISUAL
aHash
|
feff7e0081f9017c |
|
VISUAL
dHash
|
4d29d41323e32bd0 |
|
VISUAL
wHash
|
2cff7e0081f9017e |
|
VISUAL
colorHash
|
00001000380 |
|
VISUAL
cropResistant
|
0c00080880e2f8fc,24d2c0b2b2c0d222,70b0b6376ce9a7c6,9834fe8eccb8b4cc,4cce9e8699d9b0aa,d4d4da19a5b5bd3c,4d29d41323e32bd0 |
• Amenaza: Phishing
• Objetivo: Usuarios de Bet365
• Método: Suplantación de identidad y recopilación de credenciales
• Exfil: /login_action
• Indicadores: Coincidencia de dominio, ofuscación, acciones de formulario.
• Riesgo: ALTO
The attacker attempts to steal user credentials by mimicking the Bet365 login page.
The malicious domain name is similar to the legitimate Bet365 domain to deceive users.