Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1724565E16620A3AD90C7DAEDDF39DE90530F40BAB9B6D6C14ABEC75C9447D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiVC+mjK45PalP4IaJN1MSTT1OIFg1JznfngguHSVPdu3KbhDLKfUA6ly4rO43f:fqybRk+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e59613636c90f9c |
|
VISUAL
aHash
|
00183c3c1c3c3c00 |
|
VISUAL
dHash
|
4c7971713979f107 |
|
VISUAL
wHash
|
0018bdbdbdbdbd00 |
|
VISUAL
colorHash
|
0f000038001 |
|
VISUAL
cropResistant
|
f8dcacc38f5d5588,4c7971713979f107,3434b5d4d4353434 |
• Ameaça: Nenhuma ameaça detectada.
• Alvo: N/A
• Método: N/A
• Exfil: N/A
• Indicadores: Site oficial
• Risco: BAIXO - Nenhum risco detectado.
The phishing kit presents a fake Mediapart subscription or login page to trick users into entering their credentials. The harvested data is likely sent to a remote server via HTTP POST requests or JavaScript-based exfiltration.
In addition to credentials, the kit may collect personal details such as name, email, or payment information if the user proceeds with a fake subscription or account verification process.
Highly obfuscated JavaScript file likely containing credential harvesting and data exfiltration logic.
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL │
│ - Email mimics Mediapart branding │
│ - Contains link to fake login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE MEDIAPART SITE │
│ - Page replicates legitimate Mediapart interface │
│ - Displays fraudulent login form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL SUBMISSION │
│ - Victim enters Banking credentials │
│ - Form appears to submit to Mediapart │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIAL EXFILTRATION │
│ - Data sent via HTTP POST to attacker-controlled │
│ server (standard form submission) │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. VICTIM RECEIVES PHISHING EMAIL │
│ - Email mimics Mediapart branding │
│ - Contains link to fake login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM VISITS FAKE MEDIAPART SITE │
│ - Page replicates legitimate Mediapart interface │
│ - Displays fraudulent login form │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL SUBMISSION │
│ - Victim enters Banking credentials │
│ - Form appears to submit to Mediapart │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIAL EXFILTRATION │
│ - Data sent via HTTP POST to attacker-controlled │
│ server (standard form submission) │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain