Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AF4575E16620A3AD90C7DAEDDF39DE90530F40BAB9B6D6C14ABEC75C9447D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiV7+mcP20Df5eoOx24JN1MnTT1OIFg9JznfngguHSnqqKBhfEiR98UCgCZz1WQ:fqrMsFOgU0j+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
db493466629e1c9d |
|
VISUAL
aHash
|
00183c3c3c3c1c00 |
|
VISUAL
dHash
|
4c7971717969313f |
|
VISUAL
wHash
|
0018bdbdbdbdbd00 |
|
VISUAL
colorHash
|
0e200038000 |
|
VISUAL
cropResistant
|
f8dcacc38e5d5588,4c7971717969313f,3434b5d4d4353434 |
โข Threat: Website using cookies.
โข Target: Users visiting the Mediapart website.
โข Method: Cookie consent popup.
โข Exfil: No data exfiltration.
โข Indicators: Cookie consent request.
โข Risk: LOW - Standard cookie usage.
The phishing kit deploys a fake login form mimicking Mediapart's authentication portal. Submitted credentials are intercepted in real-time via JavaScript event listeners and exfiltrated to a remote server controlled by the attacker.
Additional form fields may capture sensitive personal data (e.g., name, address, phone number) under the guise of account verification or subscription management, enabling identity theft or further targeted attacks.
Highly obfuscated JavaScript file containing credential harvesting logic.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. TARGET RECEIVES PHISHING LURE โ
โ - Email/SMS with fake Mediapart Banking alert โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM CLICKS MALICIOUS LINK โ
โ - Redirects to fake Mediapart login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. FAKE LOGIN FORM DISPLAYED โ
โ - Mimics legitimate Mediapart interface โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. CREDENTIALS ENTERED & CAPTURED โ
โ - Victim submits login details โ
โ - Data collected by attacker โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 5. DATA EXFILTRATION โ
โ - Credentials sent via HTTP POST (form submission) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. TARGET RECEIVES PHISHING LURE โ
โ - Email/SMS with fake Mediapart Banking alert โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM CLICKS MALICIOUS LINK โ
โ - Redirects to fake Mediapart login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. FAKE LOGIN FORM DISPLAYED โ
โ - Mimics legitimate Mediapart interface โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. CREDENTIALS ENTERED & CAPTURED โ
โ - Victim submits login details โ
โ - Data collected by attacker โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 5. DATA EXFILTRATION โ
โ - Credentials sent via HTTP POST (form submission) โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain