Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C711CC3411B2FA33868282E8526777DF77E0425ECA830D49A3E8A39C0FDAC95FD65410 |
|
CONTENT
ssdeep
|
12:nwMwB7dwS5Euzz+K6GieelwnsvvMuvvM8Xfvy0V2fHA8:n/47dB5Euv+KDoHvK0V2I8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0bd49420f3c4f1f |
|
VISUAL
aHash
|
00cf0f4f67e5c600 |
|
VISUAL
dHash
|
949a9a8ecd8d9c4a |
|
VISUAL
wHash
|
00ef0fef67e5c600 |
|
VISUAL
colorHash
|
30201008040 |
|
VISUAL
cropResistant
|
f2961499b8b42c4e,6a7a6a6ad4d4d4d4,8cac8c9c9c9c9898,949a9a8ecd8d9c4a |
• Threat: Brand impersonation and advertisement for betting site.
• Target: Potential users interested in sports betting, especially those following the India Tour of Australia.
• Method: Displaying a 1xBet advertisement on a domain that does not belong to 1xBet, potentially redirecting users to a fraudulent website or tracking their activity.
• Exfil: Potential data exfiltration through tracking links or redirection to malicious sites.
• Indicators: Domain mismatch, advertisement on an unofficial domain.
• Risk: MEDIUM - Risk of redirection to malicious websites or tracking of user activity.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain