Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D793B8B29251243320BFB1D5F1297709A2D3D74EC68287D1B2FCA36B1ED6CA1F817856 |
|
CONTENT
ssdeep
|
1536:uMYXWnSrawluOkRor8BPmzzXXMd6MiucCOK:BYXWdwluOpkmzzXXMd6M1cCOK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a41367933c9ced98 |
|
VISUAL
aHash
|
0000dbdbffffffc3 |
|
VISUAL
dHash
|
c8c8b63638002606 |
|
VISUAL
wHash
|
000042c3dfffdfc3 |
|
VISUAL
colorHash
|
072000082c0 |
|
VISUAL
cropResistant
|
c8c8b63638002606 |
• Ameaça: Falsificação/Phishing
• Alvo: Usuários do Roblox
• Método: Falsificação de domínio e replicação de conteúdo
• Exfil: Desconhecido, provavelmente roubo de credenciais
• Indicadores: Domínio incompatível, ofuscação de JavaScript, ações de formulário para /search, detecção de envio de formulário JavaScript
• Risco: Alto
The attacker likely aims to steal Roblox account credentials through a fake login page or through social engineering tactics by mimicking the official Roblox website. JavaScript is likely used to handle login attempts, possibly sending credentials to the attacker.
The attacker may distribute malware through malicious downloads or redirects from the fake site. This is made possible via the presence of javascript obfuscation.
Found 10 other scans for this domain