Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AF4575E16620A3AD90C7DAEDDF39DE90530F40BAB9B6D6C14ABEC75C9447D80FB06814 |
|
CONTENT
ssdeep
|
3072:fxiV7+mcP20Df5eoOx24JN1MnTT1OIFg9JznfngguHSnqqKBhfEiR98UCgCZz1WQ:fqrMsFOgU0j+w9L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
db493466629e1c9d |
|
VISUAL
aHash
|
00183c3c3c3c1c00 |
|
VISUAL
dHash
|
4c7971717969313f |
|
VISUAL
wHash
|
0018bdbdbdbdbd00 |
|
VISUAL
colorHash
|
0e200038000 |
|
VISUAL
cropResistant
|
f8dcacc38e5d5588,4c7971717969313f,3434b5d4d4353434 |
• Ameaça: Site usando cookies.
• Alvo: Usuários que visitam o site Mediapart.
• Método: Pop-up de consentimento de cookies.
• Exfil: Sem exfiltração de dados.
• Indicadores: Solicitação de consentimento de cookies.
• Risco: BAIXO - Uso padrão de cookies.
The phishing kit deploys a fake login form mimicking Mediapart's authentication portal. Submitted credentials are intercepted in real-time via JavaScript event listeners and exfiltrated to a remote server controlled by the attacker.
Additional form fields may capture sensitive personal data (e.g., name, address, phone number) under the guise of account verification or subscription management, enabling identity theft or further targeted attacks.
Highly obfuscated JavaScript file containing credential harvesting logic.
┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LURE │
│ - Email/SMS with fake Mediapart Banking alert │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM CLICKS MALICIOUS LINK │
│ - Redirects to fake Mediapart login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. FAKE LOGIN FORM DISPLAYED │
│ - Mimics legitimate Mediapart interface │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIALS ENTERED & CAPTURED │
│ - Victim submits login details │
│ - Data collected by attacker │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATION │
│ - Credentials sent via HTTP POST (form submission) │
└──────────────────────────────────────────────────────────┘
┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LURE │
│ - Email/SMS with fake Mediapart Banking alert │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM CLICKS MALICIOUS LINK │
│ - Redirects to fake Mediapart login page │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 3. FAKE LOGIN FORM DISPLAYED │
│ - Mimics legitimate Mediapart interface │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 4. CREDENTIALS ENTERED & CAPTURED │
│ - Victim submits login details │
│ - Data collected by attacker │
└────────────────────┬─────────────────────────────────────┘
│
▼
┌──────────────────────────────────────────────────────────┐
│ 5. DATA EXFILTRATION │
│ - Credentials sent via HTTP POST (form submission) │
└──────────────────────────────────────────────────────────┘
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain