Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F893C8B29251243320BBB1D5F1297709A2D3D74FC68287E1B2F8636B1ED6CA1FC17856 |
|
CONTENT
ssdeep
|
1536:8mWXWnSraAKuOhkojcBPmzzXXMd6MiucCOK:9WXWdAKuOzEmzzXXMd6M1cCOK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b40667933c9cbcc9 |
|
VISUAL
aHash
|
0000dbdbffefffc3 |
|
VISUAL
dHash
|
ecec36361c1c2606 |
|
VISUAL
wHash
|
0000c3d3cfc7ffc3 |
|
VISUAL
colorHash
|
072000082c0 |
|
VISUAL
cropResistant
|
ecec36361c1c2606,244b494d49c94d4b |
• Threat: Account takeover phishing
• Target: Roblox users
• Method: Fake Roblox profile page using a deceptive domain
• Exfil: Data likely exfiltrated via JavaScript form submission to an unknown destination
• Indicators: Mismatched domain (roblox.com.kz instead of roblox.com), JavaScript obfuscation
• Risk: HIGH - Account compromise and potential data theft
Found 10 other scans for this domain