Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19E13DA72A120283761AFA3D5F515B70691D3E70ECB839BE2A2F463760AD9C31FD1341A |
|
CONTENT
ssdeep
|
768:eHXB1ly+QtF8uB1bykQPKrvrvEZ3RkWPvBRG8AEF9NpBxJ8m8:eHXB1lybtF5B13jMpRXZ9NTxJ8m8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b03057cece2c7569 |
|
VISUAL
aHash
|
c7c7c3c7fffffffe |
|
VISUAL
dHash
|
ae1e9e1e221a31c4 |
|
VISUAL
wHash
|
42c7c3c7ffff0000 |
|
VISUAL
colorHash
|
07007000080 |
|
VISUAL
cropResistant
|
ae1e9e1e221a31c4,171f1b1b17065555 |
โข Threat: Roblox game impersonation and credential harvesting phishing kit
โข Target: Roblox users
โข Method: Presents a fake Roblox game page with potential for credential theft via fake forms.
โข Exfil: Likely attempting to steal user credentials or game-related information.
โข Indicators: Unofficial domain (roblox.com.py), potential for fake forms, and impersonation of the Roblox website.
โข Risk: HIGH - Risk of credential theft and potential compromise of Roblox accounts.
The phishing kit is designed to capture Roblox account credentials by presenting a fake login form. The form likely intercepts user inputs in real-time and transmits them to a remote server controlled by the attacker.
In addition to credentials, the kit includes modules for harvesting personal information such as email addresses, phone numbers, and payment details, which can be used for further exploitation or sold on underground markets.
Large JavaScript file containing obfuscated code for credential harvesting and personal information theft.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING LURE โ
โ - Email/SMS with fake Roblox offer or alert โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM CLICKS MALICIOUS LINK โ
โ - Redirects to fake Roblox login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL HARVESTING โ
โ - Victim enters username/password in fake form โ
โ - Form captures input โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Credentials sent via HTTP POST to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING LURE โ
โ - Email/SMS with fake Roblox offer or alert โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM CLICKS MALICIOUS LINK โ
โ - Redirects to fake Roblox login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL HARVESTING โ
โ - Victim enters username/password in fake form โ
โ - Form captures input โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Credentials sent via HTTP POST to attacker server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain