Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15F33B672A1211833617B93D9F555B716A1E3E70FCA835BE2A1F8A3760AD9C31FC1341A |
|
CONTENT
ssdeep
|
1536:GJXB1/yWTC5hbjMraX4bNzO+N9NTxJ8m8:GJXBn2gbNzO+vN2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b03056cecd897d69 |
|
VISUAL
aHash
|
c7c7c3cffffffffe |
|
VISUAL
dHash
|
ae0f8e1e303c35c0 |
|
VISUAL
wHash
|
42c7c3c7cfdf0114 |
|
VISUAL
colorHash
|
072000000c1 |
|
VISUAL
cropResistant
|
ae0f8e1e303c35c0,64ec320692d2d2fa |
โข Threat: None
โข Target: Roblox users
โข Method: N/A
โข Exfil: N/A
โข Indicators: Legitimate Roblox game page
โข Risk: Low
A threat actor uses a domain similar to a real domain and shows content that appears to be related to the brand in an attempt to trick the user into doing something bad such as entering credentials.
Functions: reportMetrics, logToEventStream
User fills <input name=credentials> โ reportMetrics() โ fetch(https://metrics.roblox.com/v1/bundle-metrics/report) โ data sent to metrics API
User fills <input name=credentials> โ reportMetrics() โ fetch(https://metrics.roblox.com/v1/bundle-metrics/report) โ data sent to metrics API
bundleVerifier.jsreportMetricslogToEventStreamPages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain