Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11E83637292542437617B79CAF064771EA2D3D74FCA8246E1A2F8939A0FD6CE1F81344E |
|
CONTENT
ssdeep
|
1536:c07XWn9r03I+j9vBkX+YuOEev0ZZ7Hi7HZ7Hb7HH7HM7HY7Hp7HJ7HFZ7Hi7HN7Y:P7XWO3I8ZcruOU7C75777n7s747J7p7n |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b44747319b9cec34 |
|
VISUAL
aHash
|
0000d3ffc3c3c7ff |
|
VISUAL
dHash
|
e8e836309e1e161e |
|
VISUAL
wHash
|
0000d3dfc3c3c3ff |
|
VISUAL
colorHash
|
07201008080 |
|
VISUAL
cropResistant
|
e8e836309e1e161e |
• Amenaza: Suplantación/Phishing
• Objetivo: Usuarios de Roblox
• Método: Dominio malicioso que imita a Roblox
• Exfil: Desconocido, pero acciones de formulario y ofuscación sugieren posible robo de datos.
• Indicadores: Dominio sospechoso, ofuscación de JavaScript, formularios detectados.
• Riesgo: Alto
The attacker aims to steal Roblox account credentials through a fake login page on a lookalike domain.
A secondary method could be the download of malicious software hidden on the site.
Found 10 other scans for this domain