Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1714565E16620A3AD90C7DAEDDF39DE90530F40BAB9B6D6C14ABEC75C5487D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiVQ+QPY20o5JoKTVOX+CJldkq77dWANo1JznfngguHSAqKBhfI5R98UCQmJE2H:fqCHCtm9E+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb593466629e1c9d |
|
VISUAL
aHash
|
00183c3c3c3c3c00 |
|
VISUAL
dHash
|
4c7971717979710f |
|
VISUAL
wHash
|
0018bdbdbdbdbd00 |
|
VISUAL
colorHash
|
0e200038000 |
|
VISUAL
cropResistant
|
f8daacc38e595588,4c7971717979710f,3434b5d4d4353434 |
• Ameaça: Nenhuma detectada
• Alvo: Usuários do Mediapart
• Método: Site de notícias legítimo
• Exfil: Nenhum
• Indicadores: Domínio legítimo, nome da marca correspondente, sem conteúdo suspeito
• Risco: BAIXO - Nenhum phishing detectado
The phishing kit impersonates Mediapart to trick users into submitting login credentials via a fake authentication form. The harvested credentials are likely exfiltrated in real-time to an attacker-controlled server.
In addition to credentials, the kit may collect personal information (e.g., name, email, phone) through form fields, enabling further social engineering or identity theft.
Large obfuscated JavaScript file likely containing credential harvesting logic.
┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LURE │
│ - Email/SMS with fake Mediapart Banking alert │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM DIRECTED TO FAKE SITE │
│ - Clicks link to fraudulent Mediapart login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT │
│ - Victim enters Banking credentials in fake form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA CAPTURED & EXFILTRATED │
│ - Credentials sent via HTTP POST to attacker server │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LURE │
│ - Email/SMS with fake Mediapart Banking alert │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM DIRECTED TO FAKE SITE │
│ - Clicks link to fraudulent Mediapart login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT │
│ - Victim enters Banking credentials in fake form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA CAPTURED & EXFILTRATED │
│ - Credentials sent via HTTP POST to attacker server │
└──────────────────────────────────────────────────────────┘
Found 10 other scans for this domain