EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

http://bjeinterio.com/trillo/tripleview.html
Detected Brand
Unknown
Country
International
Confidence
95%
HTTP Status
200
Report ID
3342ae41-27a…
Analyzed
2026-02-19 23:43

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1FA41C776604569B35287D1E1B770A71FBB8282C9DF73220247F8C3AC5BC6C68DF05050
CONTENT ssdeep
24:n/CoAfDflGDeHhd/evMwvg4cmVmBcTitErsFpMuHNVNEIQrZAwpZA4VZSHaNHN9s:nmr9AeHhI7Vscgu+pPtvGow6Kyt1

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
f3c9cc2699662699
VISUAL aHash
ffffe7effee6e4fc
VISUAL dHash
28280c08284c4c30
VISUAL wHash
f6fae0e8e0e0e0d8
VISUAL colorHash
070010001c0
VISUAL cropResistant
28280c08284c4c30

Code Analysis

Risk Score 50/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Users of document access services
• Method: Impersonation and Email harvesting
• Exfil: https://metzerplaza.com/GJlYSLyO#
• Indicators: Unrelated domain, form submission to different domain, request for email.
• Risk: HIGH

🔐 Credential Harvesting Forms

📤 Form Action Targets

  • https://metzerplaza.com/GJlYSLyO#

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain mismatch and Form Action
The domain is unrelated to the content being presented and the form action points to an unrelated domain: metzerplaza.com.
Requests for sensitive information
The site requests an email address.
Impersonation
The website is designed to look like a legitimate login page

🔬 Comprehensive Threat Analysis

Threat Type
Phishing Kit (Personal Info)
Target
General public
Attack Method
Brand impersonation + credential harvesting forms
Exfiltration Channel
HTTP POST to backend
Risk Assessment
MEDIUM - Automated credential harvesting with HTTP POST to backend

⚠️ Indicators of Compromise

  • Kit types: Personal Info

🏢 Brand Impersonation Analysis

Impersonated Brand
Document Access or Secure Document Portal
Fake Service
Document Access and Verification

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The site is designed to trick users into entering their email address. This is the first step in a credential harvesting scheme. The user enters their email and the attacker will often use this information to send targeted phishing attacks.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
bjeinterio.com
Registered
None
Registrar
None
Status
Active

🤖 AI-Extracted Threat Intelligence

Scan History for bjeinterio.com

Found 1 other scan for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.