Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B54575E16620A3AD90C7DAEDDF39DE90530F40BAB9B6D6C14ABEC75C9447D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiVXGgga956sAAJN1MnTT1OIFg9JznfngguVEzqKkadF53QKdtHeEYSVdNLJw95:fqLv5dXvy5+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e4b613636cc1b99 |
|
VISUAL
aHash
|
00183c3c3c3c3c00 |
|
VISUAL
dHash
|
4c7971717979718f |
|
VISUAL
wHash
|
0018bdbdbdbdbd00 |
|
VISUAL
colorHash
|
0e400038000 |
|
VISUAL
cropResistant
|
f8dcacc38f5d5588,4c7971717979718f,3434b5d4d4353434 |
โข Threat: Privacy popup - not a threat.
โข Target: Mediapart website visitors
โข Method: Website asks about cookie preferences
โข Exfil: N/A
โข Indicators: Cookie consent
โข Risk: LOW - Standard user privacy considerations
The phishing kit impersonates Mediapart to trick users into submitting login credentials via a fake authentication form. The harvested credentials are likely exfiltrated in real-time to an attacker-controlled server.
The kit may collect additional personal information (e.g., name, email, phone) through form fields, enabling further social engineering or identity theft.
Highly obfuscated JavaScript file likely containing credential harvesting logic.
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. INITIAL ACCESS โ
โ - Victim directed to fake Mediapart Banking page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. CREDENTIAL COLLECTION โ
โ - Fake login form presented to victim โ
โ - Victim enters Banking credentials โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. DATA CAPTURE โ
โ - Form submission triggered โ
โ - Credentials collected by attacker โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. EXFILTRATION โ
โ - Credentials sent via HTTP POST โ
โ - Data transmitted to attacker-controlled server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. INITIAL ACCESS โ
โ - Victim directed to fake Mediapart Banking page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. CREDENTIAL COLLECTION โ
โ - Fake login form presented to victim โ
โ - Victim enters Banking credentials โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. DATA CAPTURE โ
โ - Form submission triggered โ
โ - Credentials collected by attacker โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. EXFILTRATION โ
โ - Credentials sent via HTTP POST โ
โ - Data transmitted to attacker-controlled server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
```
Found 10 other scans for this domain