Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1714565E16620A3AD90C7DAEDDF39DE90530F40BAB9B6D6C14ABEC75C5487D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiVQ+QPY20o5JoKTVOX+CJldkq77dWANo1JznfngguHSAqKBhfI5R98UCQmJE2H:fqCHCtm9E+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb593466629e1c9d |
|
VISUAL
aHash
|
00183c3c3c3c3c00 |
|
VISUAL
dHash
|
4c7971717979710f |
|
VISUAL
wHash
|
0018bdbdbdbdbd00 |
|
VISUAL
colorHash
|
0e200038000 |
|
VISUAL
cropResistant
|
f8daacc38e595588,4c7971717979710f,3434b5d4d4353434 |
• Amenaza: Ninguna detectada
• Objetivo: Usuarios de Mediapart
• Método: Sitio web de noticias legítimo
• Exfil: Ninguno
• Indicadores: Dominio legítimo, nombre de marca coincidente, sin contenido sospechoso
• Riesgo: BAJO - No se detectó phishing
The phishing kit impersonates Mediapart to trick users into submitting login credentials via a fake authentication form. The harvested credentials are likely exfiltrated in real-time to an attacker-controlled server.
In addition to credentials, the kit may collect personal information (e.g., name, email, phone) through form fields, enabling further social engineering or identity theft.
Large obfuscated JavaScript file likely containing credential harvesting logic.
┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LURE │
│ - Email/SMS with fake Mediapart Banking alert │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM DIRECTED TO FAKE SITE │
│ - Clicks link to fraudulent Mediapart login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT │
│ - Victim enters Banking credentials in fake form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA CAPTURED & EXFILTRATED │
│ - Credentials sent via HTTP POST to attacker server │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LURE │
│ - Email/SMS with fake Mediapart Banking alert │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM DIRECTED TO FAKE SITE │
│ - Clicks link to fraudulent Mediapart login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT │
│ - Victim enters Banking credentials in fake form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA CAPTURED & EXFILTRATED │
│ - Credentials sent via HTTP POST to attacker server │
└──────────────────────────────────────────────────────────┘
Found 10 other scans for this domain