Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19133D872A1211837A1BFA2D9F519B71591E3E70FC6835BE2A2F8A3760AC5C31FD13506 |
|
CONTENT
ssdeep
|
1536:A2+XB1LyLxGwPFl95jMQ2X06z+9NTxJ8m8:X+XBHI5p6zSN2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b03032cfc7c7654d |
|
VISUAL
aHash
|
c7c7c3c7ffffffff |
|
VISUAL
dHash
|
8e1f9e1e361e181a |
|
VISUAL
wHash
|
02c7c3c7c3c3c7c3 |
|
VISUAL
colorHash
|
07200030000 |
|
VISUAL
cropResistant
|
8e1f9e1e361e181a,65713276667b520a |
The code appears to be impersonating the Roblox website. The domain robiox.com.ua is very similar to roblox.com which is a common phishing tactic. The site includes external scripts from rbxcdn.com and google-analytics.com which would be expected on a real Roblox page but the robiox.com.ua domain in general is highly suspect. There are also redirects to the robiox.com.ua domain for Robux purchases which indicates it is trying to steal financial information.
Found 10 other scans for this domain