Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D793B8B29251243320BFB1D5F1297709A2D3D74EC68287D1B2FCA36B1ED6CA1F817856 |
|
CONTENT
ssdeep
|
1536:uMYXWnSrawluOkRor8BPmzzXXMd6MiucCOK:BYXWdwluOpkmzzXXMd6M1cCOK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a41367933c9ced98 |
|
VISUAL
aHash
|
0000dbdbffffffc3 |
|
VISUAL
dHash
|
c8c8b63638002606 |
|
VISUAL
wHash
|
000042c3dfffdfc3 |
|
VISUAL
colorHash
|
072000082c0 |
|
VISUAL
cropResistant
|
c8c8b63638002606 |
โข Threat: Impersonation/Phishing
โข Target: Roblox users
โข Method: Domain spoofing and content replication
โข Exfil: Unknown, likely credential theft
โข Indicators: Mismatched domain, JavaScript obfuscation, form actions to /search, JavaScript form submission detected
โข Risk: High
The attacker likely aims to steal Roblox account credentials through a fake login page or through social engineering tactics by mimicking the official Roblox website. JavaScript is likely used to handle login attempts, possibly sending credentials to the attacker.
The attacker may distribute malware through malicious downloads or redirects from the fake site. This is made possible via the presence of javascript obfuscation.
Found 10 other scans for this domain