Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1377154709040DC3B5543D5E8A3FAE75F37D9C1A8CA92050292F883EE5FE9D42EE61614 |
|
CONTENT
ssdeep
|
48:HJBu6PZAXcnCZNWSwvyZ71m1AcqNL6Ni5xw206NLGI/Xcm/CS/X5oqY4:nusuXwCZw+7o1ATNL6UM6BGIDPZY4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
94d67a700fc6e06d |
|
VISUAL
aHash
|
246e7e3e3e4e0400 |
|
VISUAL
dHash
|
eccce4ecf29ccc32 |
|
VISUAL
wHash
|
647e7e7e3e4e2400 |
|
VISUAL
colorHash
|
190020000c0 |
|
VISUAL
cropResistant
|
f0f8f2f09e9c94e8,39e0e0f0e2c0f8f8,6e6c7c53b6fce8e8,f9f9e1e1e0a68ecc,8280a2c2d2a280a2,a280a4e060e880b2,eccce4ecf29ccc32 |
• Ameaça: Phishing
• Alvo: Usuários do 1xBet
• Método: Imitação e colheita de credenciais
• Exfil: /register/landing_signup.php
• Indicadores: Incompatibilidade de domínio, ofuscação JavaScript, envio de formulário.
• Risco: Alto
The site uses a fake login page to trick users into entering their 1xBet credentials. These credentials are then likely sent to the attacker for unauthorized access.
The site uses a similar design to 1xBet to appear trustworthy, further encouraging users to input their credentials.
Pages with identical visual appearance (based on perceptual hash)