Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1774575E16620A3AD90C7DAEDDF39DE90530F40BAB9B6D6C14ABEC75C9447D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiVXGgBYnF5L8JN1MnTT1OIFg9JznfngguHSH+qKPb9td0H1o81eEcvoxNLJ24S:fqLukcoTH9q+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e4b6136368e1fc1 |
|
VISUAL
aHash
|
00183c3c1c1c3c00 |
|
VISUAL
dHash
|
4c7971313939718f |
|
VISUAL
wHash
|
0018bdbdbdbdbd00 |
|
VISUAL
colorHash
|
17400038000 |
|
VISUAL
cropResistant
|
f8dcaca38e5d5588,4c7971313939718f,3434b5d4d4353434 |
โข Threat: None detected
โข Target: None
โข Method: None
โข Exfil: None
โข Indicators: Legitimate domain, consistent branding
โข Risk: LOW - No phishing detected
The phishing kit deploys a fake login form mimicking Mediapart's authentication page. User inputs (e.g., email, password) are captured in real-time via JavaScript event listeners and exfiltrated to a remote server.
Beyond credentials, the kit may collect additional personal data (e.g., name, address) through hidden form fields or post-authentication profiling scripts.
Large obfuscated JavaScript file likely containing credential harvesting logic.
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. INITIAL ACCESS โ
โ - Victim directed to fake Mediapart page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. FAKE LOGIN PRESENTATION โ
โ - Legitimate-looking Banking interface displayed โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL COLLECTION โ
โ - User enters Banking credentials โ
โ - Form captures input data โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA TRANSMISSION โ
โ - Credentials sent via HTTP POST โ
โ - Standard form submission to attacker-controlled โ
โ server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. INITIAL ACCESS โ
โ - Victim directed to fake Mediapart page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. FAKE LOGIN PRESENTATION โ
โ - Legitimate-looking Banking interface displayed โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL COLLECTION โ
โ - User enters Banking credentials โ
โ - Form captures input data โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA TRANSMISSION โ
โ - Credentials sent via HTTP POST โ
โ - Standard form submission to attacker-controlled โ
โ server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
Found 10 other scans for this domain