Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11E83637292542437617B79CAF064771EA2D3D74FCA8246E1A2F8939A0FD6CE1F81344E |
|
CONTENT
ssdeep
|
1536:c07XWn9r03I+j9vBkX+YuOEev0ZZ7Hi7HZ7Hb7HH7HM7HY7Hp7HJ7HFZ7Hi7HN7Y:P7XWO3I8ZcruOU7C75777n7s747J7p7n |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b44747319b9cec34 |
|
VISUAL
aHash
|
0000d3ffc3c3c7ff |
|
VISUAL
dHash
|
e8e836309e1e161e |
|
VISUAL
wHash
|
0000d3dfc3c3c3ff |
|
VISUAL
colorHash
|
07201008080 |
|
VISUAL
cropResistant
|
e8e836309e1e161e |
โข Threat: Impersonation/Phishing
โข Target: Roblox users
โข Method: Malicious domain mimicking Roblox
โข Exfil: Unknown, but form actions and obfuscation suggest potential data theft
โข Indicators: Suspicious domain, JavaScript obfuscation, Forms detected.
โข Risk: High
The attacker aims to steal Roblox account credentials through a fake login page on a lookalike domain.
A secondary method could be the download of malicious software hidden on the site.
Found 10 other scans for this domain