Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19F13B772A1245C33A1AFA3D9F515B70591D3EB0ECB825BE2A1F8A37A09C9C71FD13416 |
|
CONTENT
ssdeep
|
768:wC2ztXB1W8yLx0QmYym3byoSPorvrvEF3gkxvBRmMF9NpBxJ8m8:wC2ztXB1LyLxdmYym3rjMl7Xl9NTxJ8F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b03033cfcfcc4c6c |
|
VISUAL
aHash
|
c7c7c3c7ffffffff |
|
VISUAL
dHash
|
8e1f0e2e363a3002 |
|
VISUAL
wHash
|
02c783c3c7c3cfc3 |
|
VISUAL
colorHash
|
070c3000000 |
|
VISUAL
cropResistant
|
8e1f0e2e363a3002,3656d7a73757d472,01c16b5e1fc4c4f0 |
• Threat: Credential harvesting phishing attack targeting Roblox users.
• Target: Roblox users, especially those in Mali or those who might mistakenly trust the domain.
• Method: The attacker uses a fake Roblox website with a malicious domain and potentially a fake login form to steal user credentials.
• Exfil: Data exfiltration is likely done through a custom API or webhook controlled by the attacker.
• Indicators: The domain name is roblox.com.ml, the TLD is .ml (Mali), Obfuscated JavaScript, Form Actions
• Risk: HIGH - Immediate credential theft and potential account compromise.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain