EN ES PT
Back to Stats

Captura Visual

Screenshot of bet63a9.com

Información de Detección

http://bet63a9.com/
Detected Brand
bet365
Country
International
Confianza
100%
HTTP Status
200
Report ID
cac99096-0f2…
Analyzed
2026-02-02 00:13
Final URL (after redirects)
https://bet63a9.com/#

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T135F251B09056AA3B02F392E0AB756B6FB3D5E2C8D943470516F8835D5FCBF94ED21092
CONTENT ssdeep
384:cwJ7vZc+VW51az/CygUyD084mR8m9Q8lz/YBN5BnA8oA:cwpRc+Vu1aG1WQ8yVKLFoA

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
cf9a71218ec6ce8c
VISUAL aHash
00003c3c3c380000
VISUAL dHash
4c9b616969631616
VISUAL wHash
ff893d3c3cb8c0c0
VISUAL colorHash
01000000e00
VISUAL cropResistant
cc82155586664c46,4c9b616969631616

Análisis de Código

Risk Score 100/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Amenaza: Phishing
• Objetivo: Usuarios de Bet365
• Método: Suplantación a través de un sitio web similar.
• Exfil: Credenciales de usuario (probablemente).
• Indicadores: Dominio engañoso, javascript ofuscado, formulario de inicio de sesión.
• Riesgo: Alto

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • eval
  • fromCharCode
  • unescape
  • document.write
  • hex_escape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • //3f38sfb.qdhyxt.com/plus/css/unite/login_modal_unite.css?ver=1738950076?v=1769993951
  • /logout
  • #normalLogin
  • //3f38sfb.qdhyxt.com/plus/css/custom/login_custom.css?ver=1663905027
  • //3f38sfb.qdhyxt.com/images_plus/main/logo.gif?ver=1612839866
  • //3f38sfb.qdhyxt.com/images_plus/footer/footer-logo.png?ver=1600719130
  • //3f38sfb.qdhyxt.com/plus/css/unite/login_unite.css?ver=1614680239
  • //3f38sfb.qdhyxt.com/plus/js/custom/login_custom.js?ver=1598008226
  • /login_action
  • //3f38sfb.qdhyxt.com/plus/js/custom/login.js?ver=1597629260
  • //3f38sfb.qdhyxt.com/plus/css/custom/login_modal_custom.css?ver=1726650059?v=1769993951

📡 API Calls Detected

  • /forgot
  • https://5sx5x5y.bipnzhh8.com/03694358abf04e8jkfle-keli6c4e59a3f8458672b518938744adfbd2b99a2ede4903545d86cda66e48a54429
  • /loadGame/
  • /prizedraw/default
  • /mbuhx0as4kui

📤 Form Action Targets

  • /login_action

📊 Desglose de Puntuación de Riesgo

Total Risk Score
90/100

Contributing Factors

Deceptive Domain
The domain does not match the brand's official domain, an immediate indicator of a phishing attempt.
Form with sensitive fields
The page contains a login form asking for sensitive information (username, password, captcha).
Obfuscated Javascript
Javascript Obfuscation detected, used to hide malicious code that steals information.
Impersonation
Site content mimics a legitimate brand (bet365).

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Banking Credential Harvester
Objetivo
bet365 users (International)
Método de Ataque
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Canal de Exfiltración
HTTP POST to backend
Evaluación de Riesgo
CRITICAL - Automated credential harvesting with HTTP POST to backend

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 72 obfuscation techniques

🏢 Análisis de Suplantación de Marca

Impersonated Brand
bet365
Official Website
https://www.bet365.com
Fake Service
bet365 login

⚔️ Metodología de Ataque

Primary Method: Credential Harvesting

The attacker sets up a fake bet365 login page that collects user credentials (username and password) entered by unsuspecting victims. The form submits the data to a server controlled by the attacker.

🌐 Indicadores de Compromiso de Infraestructura

Domain Information

Dominio
bet63a9.com
Registered
2021-07-27 12:58:23+00:00
Registrar
None
Estado
None

🔬 JavaScript Deep Analysis

Total Code Size
265,1 KB

🔗 API Endpoints Detected

Other
5

🔐 Obfuscation Detected

  • : Light
  • : None
  • : None
  • : Moderate
  • : Light
  • : Light
  • : None
  • : None
  • : Moderate
  • : None
  • : None

🤖 AI-Extracted Threat Intelligence

Scan History for bet63a9.com

Found 1 other scan for this domain

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.