EN ES PT
Back to Stats

Visual Capture

Screenshot of gruposura.life

Detection Info

https://gruposura.life/
Detected Brand
SURA
Country
International
Confidence
90%
HTTP Status
200
Report ID
1d97fb1b-fc1…
Analyzed
2026-01-26 16:57

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1CF116768C085041F4C72D0C599E2E75B55D4C5A4EA038FC076F4C318B6CEA1EDD138C0
CONTENT ssdeep
12:/TMy7FUSJEXhx0KS2N0gP0ZhEBqbSorZ6GCOe3k/csiGYb1w0WcYCf7LFslY2KLO:ACBJsA0C80Zhwq2y6n3bFLYKulBp1

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
cccc3333cccc9933
VISUAL aHash
0000183c3c180000
VISUAL dHash
100c303230300430
VISUAL wHash
30303c3c3c3c303c
VISUAL colorHash
000000001c0
VISUAL cropResistant
100c303230300430

Code Analysis

Threat Level ALTO
⚠️ Phishing Confirmed

🔬 Threat Analysis Report

• Threat: Brand impersonation phishing
• Target: SURA customers
• Method: Fake campaign page to mislead users
• Exfil: No form detected, potential data collection through interaction
• Indicators: Domain mismatch, unusual campaign name
• Risk: HIGH - Potential for data theft or misinformation

📊 Risk Score Breakdown

Total Risk Score
40/100

Contributing Factors

Brand Impersonation
Impersonates SURA brand using stolen logos and branding elements

🔬 Comprehensive Threat Analysis

Threat Type
SURA Phishing Landing Page
Target
SURA users (International)
Attack Method
Brand impersonation
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
LOW - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

🏢 Brand Impersonation Analysis

Impersonated Brand
SURA
Official Website
N/A
Fake Service
Credential harvesting service

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Malicious Landing Page

Uses SURA branding to appear legitimate in search results, social media, or advertising networks. Designed to redirect victims to phishing pages or distribute malware while maintaining appearance of authenticity.

Secondary Method: Standard Phishing Techniques

Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
gruposura.life
Registered
Unknown
Registrar
Unknown
Status
Age unknown

Hosting Information

Provider
Unknown
ASN

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.