Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CE441AF4536853F496874BE4F9711A0633A610FEFB92468883B48AD0FBE2ED9D435C61 |
|
CONTENT
ssdeep
|
3072:MBDZTa7jDw/4Q1pSBn1pSBy1pSB61pSBo1pSBafoi2cluAkYc1DI:247jDw/47g7/to |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce6131ce8e2dcf30 |
|
VISUAL
aHash
|
00003c3c3c3c0000 |
|
VISUAL
dHash
|
aadce86969697904 |
|
VISUAL
wHash
|
007e7e7f7f7c0400 |
|
VISUAL
colorHash
|
39001000c00 |
|
VISUAL
cropResistant
|
8e8999e686a68799,aadce86969697904 |
• Ameaça: Phishing
• Alvo: Usuários do bet365
• Método: Imitação de domínio e imitação da marca. Provavelmente projetado para roubar credenciais de usuário ou informações financeiras.
• Exfil: URLs WebSocket detectados, indicando potencial exfiltração de dados.
• Indicadores: Idade do domínio, incompatibilidade de domínio, ofuscação, envio de formulário JS.
• Risco: ALTO
The attackers are trying to trick users into entering their bet365 credentials on a fake login page that is almost identical to the real website, making it highly effective at impersonation.
WebSocket URLs have been detected, indicating this malicious site could be designed to covertly transmit collected data to the attacker, or receive commands and execute them without user interaction. This can potentially be used to extract sensitive information.
Pages with identical visual appearance (based on perceptual hash)