Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A14565E16620A3AD90C7DAEDDF39DE90530F40BAB976D6C14ABEC75C9487D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiVC+mpos35Zaln4jaJN1MSTT1OIFg1JznfngguVEdPdu3KbG3DLzfIA6Vy4rOe:fqyy6/9+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e59613636c90f9c |
|
VISUAL
aHash
|
00183c3c1c3c3c00 |
|
VISUAL
dHash
|
4c7971713979f18f |
|
VISUAL
wHash
|
0018bdbd3d3dfd00 |
|
VISUAL
colorHash
|
0e000038001 |
|
VISUAL
cropResistant
|
f8dcacc38e5d5588,4c7971713979f18f,3434b5d4d4353434 |
• Amenaza: La información proporcionada no representa un intento de phishing.
• Objetivo: No aplicable.
• Método: No aplicable.
• Exfil: No se indica exfiltración de datos.
• Indicadores: No hay indicadores de phishing presentes.
• Riesgo: BAJO - Contenido del sitio web legítimo.
The phishing kit deploys a credential harvester to capture user login credentials via a fake login form. The form likely mimics Mediapart's authentication process, sending stolen credentials to an attacker-controlled server in real-time.
In addition to credentials, the kit may collect personal information such as names, email addresses, or other sensitive data through form fields, enabling further targeted attacks or identity theft.
Highly obfuscated JavaScript file containing credential harvesting logic.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL │
│ - Email mimics Mediapart branding │
│ - Contains link to fake login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE MEDIAPART SITE │
│ - Page replicates legitimate Banking portal │
│ - Displays credential input form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT │
│ - Victim enters Banking credentials │
│ - Form appears identical to real Mediapart login │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Credentials sent via HTTP POST │
│ - Standard form submission to attacker-controlled │
│ server │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL │
│ - Email mimics Mediapart branding │
│ - Contains link to fake login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE MEDIAPART SITE │
│ - Page replicates legitimate Banking portal │
│ - Displays credential input form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT │
│ - Victim enters Banking credentials │
│ - Form appears identical to real Mediapart login │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION │
│ - Credentials sent via HTTP POST │
│ - Standard form submission to attacker-controlled │
│ server │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain