Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18AE265717120CC2261CF6AD8F926631080F7A71ACA8797F5F464A3F616ADC7DEA33059 |
|
CONTENT
ssdeep
|
384:wGt+1+fXXWxFONA8AqpxHe5wjh4mr8hlbhknyFWJjU9zC5j2fqtY6g:3t+1IXXWxJcemrO4gCR2CtHg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c0f6aaa222bb73a |
|
VISUAL
aHash
|
03181e331cfa98c6 |
|
VISUAL
dHash
|
87f236a2a8b2320c |
|
VISUAL
wHash
|
01191e731efabac6 |
|
VISUAL
colorHash
|
39201008040 |
|
VISUAL
cropResistant
|
87f236a2a8b2320c |
• Amenaza: Phishing por suplantación de identidad
• Objetivo: Usuarios de Roblox
• Método: Recopilación de credenciales a través de un formulario de inicio de sesión falso
• Exfil: JavaScript potencialmente utilizado para exfiltrar datos
• Indicadores: Discordancia de dominio, JavaScript ofuscado, envío de formulario.
• Riesgo: Alto
The attacker creates a fake login page that mimics the Roblox signup page. When a user enters their credentials, the site likely captures them.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain