Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T116D1C7901443BD0D476711DBDAC7C75AD3EF4382D2317A8AD2ACCAB512C5F8AD5A321A |
|
CONTENT
ssdeep
|
96:vHtyLw7XLpfVHBW1hhLpnvOe2S7pa6rLR57lH1gKdKW+4ItYJnKa21Oiz:v2mVkDXtTgKz+4KYtr28I |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c76d313c9a3c3465 |
|
VISUAL
aHash
|
3c70303c3c3c3c3c |
|
VISUAL
dHash
|
c8c1c8e9c8e4c8cc |
|
VISUAL
wHash
|
7c70743c3c3c3c3c |
|
VISUAL
colorHash
|
38003000600 |
|
VISUAL
cropResistant
|
c8c1c8e9c8e4c8cc |
• Ameaça: Phishing/Fraude de afiliados
• Alvo: Usuários do Bets10
• Método: Typosquatting/Impersonação de domínio para redirecionamento
• Exfil: Desconhecido (redirecionamentos)
• Indicadores: Domínio recente, impersonação de marca de apostas
• Risco: Alto
Uses 'look-alike' domain to intercept users searching for official gambling login addresses.
Redirects users to malicious or tracked external gambling links.