EN ES PT
Back to Stats

Visual Capture

Screenshot of www.flowcode.com

Detection Info

https://www.flowcode.com/page/redirect-attsecurepayment1
Detected Brand
AT&T
Country
USA
Confidence
100%
HTTP Status
200
Report ID
36a888df-e89…
Analyzed
2026-01-01 02:45
Final URL (after redirects)
https://www.flow.page/redirect-attsecurepayment1

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1416296F6B2C1AD2B932331D8F1D2F3CEF043620EDAC94694B5BD07B552DACB240159A9
CONTENT ssdeep
384:Hw1F4V+8B1pd/cB3B7PdyC9N9FXWKeWnGoCglYCCgtNC33:Hw12VjB1ncNdoSN/GmYgNC3

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
aa35ca35ca35ca35
VISUAL aHash
00000000000000ff
VISUAL dHash
0e0e091e1b1f1ec9
VISUAL wHash
03070b0f0f0f0fff
VISUAL colorHash
00007000000
VISUAL cropResistant
8d00c9c149c980c9,0e0e091f131b120f

Code Analysis

Risk Score 95/100
Threat Level MEDIO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Phishing attempt targeting AT&T customers.
• Target: AT&T customers.
• Method: The attacker uses a domain that does not belong to AT&T, showing AT&T logos to trick users into clicking the button.
• Exfil: Unknown, potentially redirects to another phishing page or steals information on click.
• Indicators: Domain mismatch, AT&T logo, billing information text.
• Risk: MEDIUM - The page could lead to credential harvesting or financial theft.

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • hex_escape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • https://flow.page/privacy-policy#notice-at-collection

📡 API Calls Detected

  • GET
  • /api/social-validation/youtube?handle=
  • POST
  • /api/social-validation/facebook?handle=
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.