EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

http://admin-ods.insolvency-development.co.uk
Detected Brand
GOV.UK
Country
UK
Confidence
95%
HTTP Status
200
Report ID
3dbcf76e-068…
Analyzed
2025-12-20 17:48
Final URL (after redirects)
https://admin-ods.insolvency-development.co.uk/Account/Login?ReturnUrl=%2F

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T11BD17335A4195D2A0713EBC1F3A2737AD293C289C7560D0495FC47EE0BEAE95CC5A323
CONTENT ssdeep
96:Ws0lGTGiSGvRGmGmIKWGlHtCrFzbX2BRGxR6EkopXPFssPbG/ZC0myJ:WsysnS6RfRWKHSofMR6EkcbGSa

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
bc34636167366963
VISUAL aHash
00ffffff0000ffff
VISUAL dHash
1e003020223a0400
VISUAL wHash
00ffdfdf0000c0ff
VISUAL colorHash
070000003c0
VISUAL cropResistant
3a203228323a0c00,403048484a489616

Code Analysis

Risk Score 70/100
Threat Level ALTO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing targeting UK government users.
• Target: Users of GOV.UK services, specifically those related to The Insolvency Service.
• Method: Presents a fake login form to steal usernames and passwords.
• Exfil: Unknown data exfiltration point.
• Indicators: Domain mismatch (admin-ods.insolvency-development.co.uk vs. gov.uk), login form.
• Risk: HIGH - Immediate risk of credential theft and potential unauthorized access to government services.

🔐 Credential Harvesting Forms

🎯 Kit Endpoints

  • /Account/Login?ReturnUrl=%2F

📤 Form Action Targets

  • /Account/Login?ReturnUrl=%2F
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.