Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12483857292542437617B79CAF064771AA2D3D74FCA8246E1A2F8939A0FD6CE1FC1740E |
|
CONTENT
ssdeep
|
1536:rEZXWn9rt51+Be4dr5PNYuOVeVFZv7Hg7Hz7HO7HS7HI7Hb7Hn7Hm7Hk7He7HO7z:oZXWn51GBFOuOy7A7T7u7y7o777H7G7m |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0471363c798ecbc |
|
VISUAL
aHash
|
0000d3ffc3c3dfff |
|
VISUAL
dHash
|
e8c8b63016063032 |
|
VISUAL
wHash
|
0000c3dfc3c3cfdf |
|
VISUAL
colorHash
|
070010080c0 |
|
VISUAL
cropResistant
|
e8c8b63016063032,37376751192747a7 |
• Amenaza: No se detectó ninguna amenaza.
• Objetivo: Usuarios de Roblox.
• Método: Contenido legítimo del sitio web de Roblox.
• Exfil: No se detectó exfiltración.
• Indicadores: No hay indicadores sospechosos.
• Riesgo: BAJO - Contenido legítimo.
The phishing kit deploys a credential harvester that intercepts user inputs in real-time via form fields labeled 'Sign Up', 'Log In', 'Join', and 'Add Connection'. The harvested credentials are likely exfiltrated to a remote server for immediate use in account takeover attacks.
The kit includes an OTP stealer and card stealer module, designed to capture one-time passwords and payment card details. This enables attackers to bypass multi-factor authentication and conduct unauthorized transactions.
Obfuscated JavaScript files containing credential harvesting, OTP stealing, and card skimming functionality.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE │
│ - Email/SMS with fake Roblox login link │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE ROBLOX SITE │
│ - Clones official Roblox login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT │
│ - Victim enters username/password │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIAL HARVESTING │
│ - Form captures input data │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATION │
│ - HTTP POST submits credentials to attacker server │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING LURE │
│ - Email/SMS with fake Roblox login link │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE ROBLOX SITE │
│ - Clones official Roblox login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT │
│ - Victim enters username/password │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIAL HARVESTING │
│ - Form captures input data │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATION │
│ - HTTP POST submits credentials to attacker server │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain