Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A4F1CE311054EC3302A7E1DA97B81B9F76E5962ADE53464B9BF8874E4FDBC80CD62221 |
|
CONTENT
ssdeep
|
192:C7vTIz2Tp+ps8Rrd3TDMFPdfT+BH1GR/vu/9:OT3Qs8RrlTYF1fCBVGRvu/9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b39966269931e6cc |
|
VISUAL
aHash
|
9ba5bdddbda5e7df |
|
VISUAL
dHash
|
304c2a5a324d4c32 |
|
VISUAL
wHash
|
33407e2cbda5c783 |
|
VISUAL
colorHash
|
07000000038 |
|
VISUAL
cropResistant
|
304c2a5a324d4c32 |
⢠Threat: Phishing
⢠Target: Roblox users
⢠Method: Impersonation with username harvesting.
⢠Exfil: JavaScript with obfuscation likely attempts exfiltration
⢠Indicators: 'Robux Booster', username form, suspicious domain.
⢠Risk: High
The site attempts to collect Roblox usernames by providing a fake login prompt.
Obfuscated Javascript used to mask malicious intent or potential exfiltration attempts.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain