Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1184565E16620A3AD90C7DAEDDF39DE90530F40BAB9B6D6C14ABEC75C9447D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiVQ+QNMp1+Sk5T7oJV27CJldkq77dWANo1JznfngguHSVdqPuLMfI5s1G87I7C:fqCNreqG+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb1f2466629c1dcb |
|
VISUAL
aHash
|
00183c3c3c3c1800 |
|
VISUAL
dHash
|
4c7971717979638f |
|
VISUAL
wHash
|
0018bdbdbdbdbd00 |
|
VISUAL
colorHash
|
0e001038000 |
|
VISUAL
cropResistant
|
f8dcacc38e595588,4c7971717979638f,3434b5d4d4353434 |
• Ameaça: Nenhuma
• Alvo: Nenhum
• Método: Nenhum
• Exfil: Nenhum
• Indicators: Popup de consentimento de cookie normal
• Risk: BAIXO - Consentimento normal de cookies do site
The phishing kit deploys a credential harvester to capture user login details via a fake Mediapart login or subscription form. The harvested credentials are likely exfiltrated in real-time to an attacker-controlled server.
In addition to credentials, the kit collects personal information such as names, email addresses, and potentially payment details through form fields, enabling further targeted attacks or identity theft.
Highly obfuscated JavaScript file containing credential harvesting and personal information theft logic.
┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LURE │
│ - Email/SMS with fake Mediapart Banking alert │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM CLICKS MALICIOUS LINK │
│ - Redirected to fake Mediapart login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. FAKE LOGIN FORM DISPLAYED │
│ - Credentials requested via spoofed interface │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIALS ENTERED & CAPTURED │
│ - User submits login details │
│ - Data collected by attacker │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATED │
│ - Credentials sent via HTTP POST (form submission) │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LURE │
│ - Email/SMS with fake Mediapart Banking alert │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM CLICKS MALICIOUS LINK │
│ - Redirected to fake Mediapart login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. FAKE LOGIN FORM DISPLAYED │
│ - Credentials requested via spoofed interface │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIALS ENTERED & CAPTURED │
│ - User submits login details │
│ - Data collected by attacker │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATED │
│ - Credentials sent via HTTP POST (form submission) │
└──────────────────────────────────────────────────────────┘
Found 10 other scans for this domain