Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E893C8B29251243320BFB1D5F1297709A2D3D74EC68287E1F2F8636B1ED6CA1F817856 |
|
CONTENT
ssdeep
|
1536:oz5XWnSraDDuOdpor8BPmzzXXMd6MiucCOK:Q5XWdDDuO+kmzzXXMd6M1cCOK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e41263933ccced99 |
|
VISUAL
aHash
|
0000fbdbffffffc3 |
|
VISUAL
dHash
|
e8e8a63638002606 |
|
VISUAL
wHash
|
000010d3dfffdfc3 |
|
VISUAL
colorHash
|
070000082c0 |
|
VISUAL
cropResistant
|
e8e8a63638002606 |
• Ameaça: Falsificação/Phishing
• Alvo: Usuários do Roblox
• Método: Domínio malicioso imitando o site original
• Exfil: Provavelmente rouba credenciais
• Indicadores: Incompatibilidade de domínio, código ofuscado
• Risco: Alto
The site likely attempts to steal login credentials through a fake login page. After the user submits the login information, it will be sent to the attackers. The presence of form actions, obfuscation and JavaScript submission support this claim.
User fills <input name='username'> → sendData() → fetch('https://api.roblox.com') → credentials sent to attacker
User fills <input name='username'> → sendData() → fetch('https://api.roblox.com') → credentials sent to attacker
0c2a7c793ed0761b93b214956992ffb44014abcb404fd8bd2f9a7eb32ea0a600.jssendDatasubmitFormFound 7 other scans for this domain