Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1774575E16620A3AD90C7DAEDDF39DE90530F40BAB9B6D6C14ABEC75C9447D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiVXGgBYnF5L8JN1MnTT1OIFg9JznfngguHSH+qKPb9td0H1o81eEcvoxNLJ24S:fqLukcoTH9q+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9e4b6136368e1fc1 |
|
VISUAL
aHash
|
00183c3c1c1c3c00 |
|
VISUAL
dHash
|
4c7971313939718f |
|
VISUAL
wHash
|
0018bdbdbdbdbd00 |
|
VISUAL
colorHash
|
17400038000 |
|
VISUAL
cropResistant
|
f8dcaca38e5d5588,4c7971313939718f,3434b5d4d4353434 |
• Ameaça: Nenhuma detectada
• Alvo: Nenhum
• Método: Nenhum
• Exfil: Nenhum
• Indicadores: Domínio legítimo, marca consistente
• Risco: BAIXO - Não foi detectado phishing
The phishing kit deploys a fake login form mimicking Mediapart's authentication page. User inputs (e.g., email, password) are captured in real-time via JavaScript event listeners and exfiltrated to a remote server.
Beyond credentials, the kit may collect additional personal data (e.g., name, address) through hidden form fields or post-authentication profiling scripts.
Large obfuscated JavaScript file likely containing credential harvesting logic.
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
┌──────────────────────────────────────────────────────────┐
│ 1. INITIAL ACCESS │
│ - Victim directed to fake Mediapart page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE LOGIN PRESENTATION │
│ - Legitimate-looking Banking interface displayed │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL COLLECTION │
│ - User enters Banking credentials │
│ - Form captures input data │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA TRANSMISSION │
│ - Credentials sent via HTTP POST │
│ - Standard form submission to attacker-controlled │
│ server │
└──────────────────────────────────────────────────────────┘
```
Here's a generic ASCII art attack flow diagram for the phishing attack:
```
┌──────────────────────────────────────────────────────────┐
│ 1. INITIAL ACCESS │
│ - Victim directed to fake Mediapart page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE LOGIN PRESENTATION │
│ - Legitimate-looking Banking interface displayed │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL COLLECTION │
│ - User enters Banking credentials │
│ - Form captures input data │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA TRANSMISSION │
│ - Credentials sent via HTTP POST │
│ - Standard form submission to attacker-controlled │
│ server │
└──────────────────────────────────────────────────────────┘
```
Found 10 other scans for this domain