Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A14565E16620A3AD90C7DAEDDF39DE90530F40BAB976D6C14ABEC75C9487D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiVC+mpos35Zaln4jaJN1MSTT1OIFg1JznfngguVEdPdu3KbG3DLzfIA6Vy4rOe:fqyy6/9+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e59613636c90f9c |
|
VISUAL
aHash
|
00183c3c1c3c3c00 |
|
VISUAL
dHash
|
4c7971713979f18f |
|
VISUAL
wHash
|
0018bdbd3d3dfd00 |
|
VISUAL
colorHash
|
0e000038001 |
|
VISUAL
cropResistant
|
f8dcacc38e5d5588,4c7971713979f18f,3434b5d4d4353434 |
โข Threat: The provided information does not represent a phishing attempt.
โข Target: Not applicable.
โข Method: Not applicable.
โข Exfil: No data exfiltration is indicated.
โข Indicators: No phishing indicators are present.
โข Risk: LOW - Legitimate website content.
The phishing kit deploys a credential harvester to capture user login credentials via a fake login form. The form likely mimics Mediapart's authentication process, sending stolen credentials to an attacker-controlled server in real-time.
In addition to credentials, the kit may collect personal information such as names, email addresses, or other sensitive data through form fields, enabling further targeted attacks or identity theft.
Highly obfuscated JavaScript file containing credential harvesting logic.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING EMAIL โ
โ - Email mimics Mediapart branding โ
โ - Contains link to fake login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM VISITS FAKE MEDIAPART SITE โ
โ - Page replicates legitimate Banking portal โ
โ - Displays credential input form โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL INPUT โ
โ - Victim enters Banking credentials โ
โ - Form appears identical to real Mediapart login โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Credentials sent via HTTP POST โ
โ - Standard form submission to attacker-controlled โ
โ server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 1. VICTIM RECEIVES PHISHING EMAIL โ
โ - Email mimics Mediapart branding โ
โ - Contains link to fake login page โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 2. VICTIM VISITS FAKE MEDIAPART SITE โ
โ - Page replicates legitimate Banking portal โ
โ - Displays credential input form โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 3. CREDENTIAL INPUT โ
โ - Victim enters Banking credentials โ
โ - Form appears identical to real Mediapart login โ
โโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ 4. DATA EXFILTRATION โ
โ - Credentials sent via HTTP POST โ
โ - Standard form submission to attacker-controlled โ
โ server โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain