Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AB93B9B29251243320BFB1D5F1297709A2D3D74EC68287E1E2FC636B1ED6CA1F817856 |
|
CONTENT
ssdeep
|
1536:YPpXWnSraLquOVJor8BPmzzXXMd6MiucCOK:8pXWdLquO+kmzzXXMd6M1cCOK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e41267933c9ced91 |
|
VISUAL
aHash
|
0000f3dbffffffc3 |
|
VISUAL
dHash
|
e8e8a63638002606 |
|
VISUAL
wHash
|
000042c3dfffdfc3 |
|
VISUAL
colorHash
|
07002000080 |
|
VISUAL
cropResistant
|
e8e8a63638002606 |
โข Threat: Roblox phishing site designed to steal account credentials.
โข Target: Roblox users, likely in Spain, or Spanish speaking countries.
โข Method: A fake Roblox login page is used to harvest usernames and passwords.
โข Exfil: Unknown, but likely exfiltrates credentials via a custom API or to a compromised server.
โข Indicators: The domain does not match the official Roblox website, obfuscated Javascript, form actions present, JavaScript form submission detected, country code TLD.
โข Risk: HIGH - Stolen credentials can lead to account compromise, loss of virtual items, and potential financial fraud.
The phishing kit is designed to capture Roblox account credentials by presenting a fake login form. Submitted credentials are likely exfiltrated in real-time to an attacker-controlled server for immediate account takeover and further exploitation.
The kit includes modules for intercepting one-time passwords (OTPs) and stealing payment card details. Users may be prompted to enter OTPs or card information under the guise of account verification or premium service upgrades.
Large obfuscated JavaScript file containing credential harvesting and data exfiltration logic.
Found 10 other scans for this domain