Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1724565E16620A3AD90C7DAEDDF39DE90530F40BAB9B6D6C14ABEC75C9447D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiVC+mjK45PalP4IaJN1MSTT1OIFg1JznfngguHSVPdu3KbhDLKfUA6ly4rO43f:fqybRk+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e59613636c90f9c |
|
VISUAL
aHash
|
00183c3c1c3c3c00 |
|
VISUAL
dHash
|
4c7971713979f107 |
|
VISUAL
wHash
|
0018bdbdbdbdbd00 |
|
VISUAL
colorHash
|
0f000038001 |
|
VISUAL
cropResistant
|
f8dcacc38f5d5588,4c7971713979f107,3434b5d4d4353434 |
โข Threat: No threat detected.
โข Target: N/A
โข Method: N/A
โข Exfil: N/A
โข Indicators: Official website
โข Risk: LOW - No risk detected.
The phishing kit presents a fake Mediapart subscription or login page to trick users into entering their credentials. The harvested data is likely sent to a remote server via HTTP POST requests or JavaScript-based exfiltration.
In addition to credentials, the kit may collect personal details such as name, email, or payment information if the user proceeds with a fake subscription or account verification process.
Highly obfuscated JavaScript file likely containing credential harvesting and data exfiltration logic.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING EMAIL โ
โ - Email mimics Mediapart branding โ
โ - Contains link to fake login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM VISITS FAKE MEDIAPART SITE โ
โ - Page replicates legitimate Mediapart interface โ
โ - Displays fraudulent login form โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL SUBMISSION โ
โ - Victim enters Banking credentials โ
โ - Form appears to submit to Mediapart โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. CREDENTIAL EXFILTRATION โ
โ - Data sent via HTTP POST to attacker-controlled โ
โ server (standard form submission) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING EMAIL โ
โ - Email mimics Mediapart branding โ
โ - Contains link to fake login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM VISITS FAKE MEDIAPART SITE โ
โ - Page replicates legitimate Mediapart interface โ
โ - Displays fraudulent login form โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL SUBMISSION โ
โ - Victim enters Banking credentials โ
โ - Form appears to submit to Mediapart โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. CREDENTIAL EXFILTRATION โ
โ - Data sent via HTTP POST to attacker-controlled โ
โ server (standard form submission) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain