Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EC5409F8835813B1968B8BD4F8B15A1A339611AFEB92475883F48AD0FFE2EC5D435C51 |
|
CONTENT
ssdeep
|
3072:MZD6ATa7jDw/4Q1pSBn1pSBy1pSB61pSBo1pSBafoi2cluAkYc1DI:i6D7jDw/47g7/to |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce6131ce8e2dcf30 |
|
VISUAL
aHash
|
00003c3c3c3c0000 |
|
VISUAL
dHash
|
aadce8696969790c |
|
VISUAL
wHash
|
007e7e7f7f7c0400 |
|
VISUAL
colorHash
|
39001000c00 |
|
VISUAL
cropResistant
|
8e8999e686a68799,aadce8696969790c |
• Ameaça: Phishing
• Alvo: Usuários do Bet365
• Método: Falsificação de domínio e personificação da marca
• Exfil: wss://tp-woekdksdiu-md-wdielskdks-socket.abcsport2.com
• Indicadores: Domínio não relacionado, registro recente, detecção de ofuscação, envio de formulário JS.
• Risco: Alto
The attacker uses a fake login page to trick users into entering their Bet365 username and password.
The site may be attempting to distribute malware either through drive-by downloads or through the use of malicious redirects that lead the user to a malware download.
Pages with identical visual appearance (based on perceptual hash)