EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

http://seasolutions.com/Build_Up/verification.html
Detected Brand
Unknown
Country
International
Confidence
95%
HTTP Status
200
Report ID
3630736f-b2d…
Analyzed
2026-01-30 08:28

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1FA41C776604569B35287D1E1B770A71FBB8282C9DF73220247F8C3AC5BC6C68DF05050
CONTENT ssdeep
24:n/CoAfDflGDeHhd/evMwvg4cmVmBcTitErsFpMuHNVNEIQrZAwpZA4VZSHaNHN9s:nmr9AeHhI7Vscgu+pPtvGow6Kyt1

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
f3c9cc2699662699
VISUAL aHash
ffffe7effee6e4fc
VISUAL dHash
28280c08284c4c30
VISUAL wHash
f6fae0e8e0e0e0d8
VISUAL colorHash
070010001c0
VISUAL cropResistant
28280c08284c4c30

Code Analysis

Risk Score 50/100
Threat Level ALTO
āš ļø Phishing Confirmed
šŸŽ£ Personal Info

šŸ”¬ Threat Analysis Report

• Threat: Phishing
• Target: Unspecified (likely users expecting secure document access)
• Method: Impersonation and credential harvesting via email verification form.
• Exfil: https://metzerplaza.com/GJlYSLyO#
• Indicators: Unrelated domain, form submission to suspicious domain.
• Risk: High

šŸ” Credential Harvesting Forms

šŸ“¤ Form Action Targets

  • https://metzerplaza.com/GJlYSLyO#

šŸ“Š Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Form submission to a suspicious domain
The form action points to an external domain that is most likely the exfiltration point for user data.
Domain Unrelated to Content
The domain seasolutions.com is not related to the branding presented in the screenshot. The domain may be compromised.
Requests for sensitive information
The page asks for an email address, which is sensitive information, and requests email verification. This is a method of credential harvesting.

šŸ”¬ Comprehensive Threat Analysis

Threat Type
Phishing Kit (Personal Info)
Target
General public
Attack Method
credential harvesting forms
Exfiltration Channel
HTTP POST to backend
Risk Assessment
MEDIUM - Automated credential harvesting with HTTP POST to backend

āš ļø Indicators of Compromise

  • Kit types: Personal Info

šŸ¢ Brand Impersonation Analysis

Impersonated Brand
Secure Document Portal
Fake Service
Secure Document Portal

Fraudulent Claims

āš”ļø Attack Methodology

Primary Method: Credential Harvesting

The attacker is attempting to steal user's email address by tricking them into entering it into a form under the guise of verifying document access.

Secondary Method: Malicious Redirection

The form submission redirects the user to a malicious domain (metzerplaza.com), which is then used to harvest the stolen data.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
seasolutions.com
Registered
2000-01-22T19:45:10+00:00
Registrar
Namecheap, Inc.
Status
ACTIVE

šŸ¤– AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.