EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

http://id-handel-mobile-de.12635033-52-20190820094605.webstarterz.com
Detected Brand
mobile.de
Country
Germany
Confidence
95%
HTTP Status
200
Report ID
1d61f9ec-3c1…
Analyzed
2025-12-22 13:56
Final URL (after redirects)
http://id-handel-mobile-de.12635033-52-20190820094605.webstarterz.com/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T16AF1EAA1A95495B7E18187E8F2B1D559724F9165CBB70A08D3ECCF582FE5E80CC43D90
CONTENT ssdeep
96:2X9S/3TD8sbb17KBdBurpURmHjs0VAylzJj8nfgNbTO2gvrWKeA6VHD4X4Ks:+S8sY91k40VdOnfgNbKFTWKeDHDK4D

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b838c6ce38cec339
VISUAL aHash
ffcfcfc3cfcfffff
VISUAL dHash
309c9c969c986210
VISUAL wHash
dfcfcfc34e4e0000
VISUAL colorHash
07007200000
VISUAL cropResistant
309c9c969c986210,ffff7f9f9fffff69,87a7ad2f2627e647

Code Analysis

Risk Score 70/100
Threat Level ALTO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Credential phishing attack
• Target: Dealers using mobile.de in Germany
• Method: Fake login page to steal usernames/emails and passwords
• Exfil: Likely to a remote server under attacker control
• Indicators: Domain mismatch, long and suspicious domain name on a free hosting site (webstarterz.com)
• Risk: HIGH - Potential for immediate credential theft and account compromise

🔐 Credential Harvesting Forms

📤 Form Action Targets

  • save.php

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.