Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BA43E9B2E1202837517FB6D6F469B30691D3D70ECA8657E2A1F863660EDACA1FC17407 |
|
CONTENT
ssdeep
|
768:09KXWnhrqRQXkCl2WUj4MYuO5BeVP2tT2jWZ2pz2OH2Az22P2tT2jqZ2rLXpmY8J:09KXWnhrTXjUj4MYuOzexLpt8mg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b6366343999c9ccc |
|
VISUAL
aHash
|
0000d3dfffffffff |
|
VISUAL
dHash
|
cccd36340c000206 |
|
VISUAL
wHash
|
000000cfcfffffc3 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
cccd36340c000206,7171311907862626 |
• Amenaza: Impersonación/Phishing
• Objetivo: Usuarios de Roblox
• Método: Suplantación de dominio y mimicry de la interfaz de usuario.
• Exfil: Potencialmente datos de formulario (credenciales), basado en análisis de Javascript.
• Indicadores: Coincidencia de dominio, ofuscación de Javascript, mimicry de la interfaz de usuario.
• Riesgo: Alto
The site likely attempts to steal login credentials through a fake login form or social engineering techniques, using the look and feel of Roblox's website to deceive users.
The obfuscated Javascript may be designed to deliver a malicious payload, or perform other malicious activity, such as keylogging or information exfiltration.
EnvironmentUrls.js?v=293815115Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain