Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FCE20EB09156AA3B02F392F1ABB52B5EB3C5E2C9D903470416FCC39D4FCBE84E922551 |
|
CONTENT
ssdeep
|
384:dqj1r8g+VW5YKaQ8Qh3oWCygUyD084mR8m9Rd6zK:dqV8g+VWYvQ8Qh3oZ1WQ8yYK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93b3437e3e4645c1 |
|
VISUAL
aHash
|
ffff7f87ff000000 |
|
VISUAL
dHash
|
4d18d02d38c06961 |
|
VISUAL
wHash
|
ffff7f07cf000000 |
|
VISUAL
colorHash
|
03001000380 |
|
VISUAL
cropResistant
|
0c00080880e3f8fc,899b920e1c314105,24d2c0b2b2c0d222,b4a4dd361e6ce998,2ecee6f2cc8c8894,61cc5828d5cf2ecb,4d18d02d38c06961 |
• Threat: Credential harvesting phishing kit targeting Bet365 users.
• Target: Bet365 customers internationally.
• Method: Fake login form steals usernames and passwords.
• Exfil: Data exfiltration target unknown, likely a custom API or database.
• Indicators: Domain mismatch (bet83099.com vs. bet365.com), login form, and impersonation of the Bet365 brand.
• Risk: HIGH - Real-time credential theft leading to account compromise.
Found 6 other scans for this domain