EN ES PT
Back to Stats

Visual Capture

Screenshot of ryukendo-rahul.github.io

Detection Info

http://ryukendo-rahul.github.io/amazon_clone
Detected Brand
Amazon
Country
International
Confidence
95%
HTTP Status
200
Report ID
1ee2bfb0-a5d…
Analyzed
2026-02-17 04:44
Final URL (after redirects)
https://ryukendo-rahul.github.io/amazon_clone/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1C6324960104AFA33159383E59B3A979E7BC5C248C8724F0653FC93CE2ADBD4BDD62529
CONTENT ssdeep
96:n/9XuyqOxmT51EChHYttTUHKKuwykRh0hKCMhTzP6Upi5:/9XukxI5q1ifFEKCMhTzP6Mi5

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
da0d4e4b47cb424f
VISUAL aHash
0000dfffeefcfffe
VISUAL dHash
f13634d751992954
VISUAL wHash
000082ffa8fcffb6
VISUAL colorHash
072c1000000
VISUAL cropResistant
a2a2a2a2a2a280a2,3036af57d1ad6954,d1c1f00f913037b6

Code Analysis

Risk Score 50/100
Threat Level ALTO
āš ļø Phishing Confirmed
šŸŽ£ Banking

šŸ”¬ Threat Analysis Report

• Threat: Phishing
• Target: Amazon customers
• Method: Impersonation through a cloned website on free hosting.
• Exfil: Likely to steal credentials or financial information.
• Indicators: Free hosting, Amazon logo, cloned content.
• Risk: HIGH

šŸ“Š Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Free Hosting
The site is hosted on a free hosting platform (github.io), often used by phishers to deploy fake websites.
Brand Impersonation
The website attempts to mimic the Amazon website and content.
Cloned Content
The entire content is a replica of a legitimate brand's website.

šŸ”¬ Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Amazon users (International)
Attack Method
Brand impersonation
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

āš ļø Indicators of Compromise

  • Kit types: Banking

šŸ¢ Brand Impersonation Analysis

Impersonated Brand
Amazon
Official Website
https://www.amazon.in/
Fake Service
Amazon India website.

āš”ļø Attack Methodology

Primary Method: Credential Harvesting

The attacker aims to steal user credentials by mimicking the Amazon login page. Users entering credentials on the fake site will unknowingly give their login information to the attacker.

Secondary Method: Malware distribution

Malicious code is not detected in this snapshot. If forms were present they could download and execute malicious code via JavaScript injections.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
ryukendo-rahul.github.io
Registered
Unknown
Registrar
Unknown
Status
Active

šŸ¤– AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.