Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18793B8B29251243360BBB1D5F1297709A2D3D74EC68287E1F2F8636B1EC6CA1FC17856 |
|
CONTENT
ssdeep
|
1536:SbfXWnSraf9uOHwoj8BPmzzXXMd6MiucCOK:WfXWdf9uORkmzzXXMd6M1cCOK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b40367936c8cecd9 |
|
VISUAL
aHash
|
0000dbdbffcfffc3 |
|
VISUAL
dHash
|
e8c83636180c2606 |
|
VISUAL
wHash
|
0000d3d3cfc7dfc3 |
|
VISUAL
colorHash
|
072000082c0 |
|
VISUAL
cropResistant
|
e8c83636180c2606 |
⢠Threat: Roblox account takeover phishing.
⢠Target: Roblox users.
⢠Method: Uses a fake Roblox page to potentially steal login information.
⢠Exfil: Potentially steals login credentials or encourages downloading malware.
⢠Indicators: Mismatched domain (robloxv.com.es instead of roblox.com), obfuscated JavaScript, and potentially requests sensitive information via a form.
⢠Risk: MODERATE - Potential account compromise.
Found 7 other scans for this domain