Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19F93B8B29251243320BFB1D9F1297709A2D3D74EC68287E1F2F8536B1ED6CA1F817856 |
|
CONTENT
ssdeep
|
1536:0aCXWnSraYIuOiforMBPmzzXXMd6MiucCOK:JCXWdYIuO10mzzXXMd6M1cCOK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b41263d33c9cccd9 |
|
VISUAL
aHash
|
0000dbdbffffffc3 |
|
VISUAL
dHash
|
e8c8363618002606 |
|
VISUAL
wHash
|
000003c3dfffdfc3 |
|
VISUAL
colorHash
|
07200008280 |
|
VISUAL
cropResistant
|
e8c8363618002606,9d99712533159c8c |
• Threat: Roblox account phishing
• Target: Roblox users
• Method: Fake Roblox profile page to steal credentials
• Exfil: Unknown
• Indicators: Unofficial domain (roblox.com.kz), form actions, obfuscated javascript
• Risk: HIGH - Account takeover
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain