EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

https://gts.com.uy/code89765456478
Detected Brand
Unknown
Country
International
Confidence
95%
HTTP Status
200
Report ID
5d812e1b-b9c…
Analyzed
2026-02-24 07:27
Final URL (after redirects)
https://gts.com.uy/code89765456478/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1C241A676604569B35287D2F1B770A71FBB828286DF67220257F8C3AC5AC6C58DE01051
CONTENT ssdeep
24:n/CoAfDflGDeHhd/evMwvg452TpmBcTitErsFpMuHNVNEIQrZAwpZA4VZSHaNHN2:nmr9AeHhI5escgu+pPtvGow6Kyt1

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
f3c9cc2699662699
VISUAL aHash
ffffe7effee6e4fc
VISUAL dHash
28280c08284c4c30
VISUAL wHash
f6fae0e8e0e0e0d8
VISUAL colorHash
070010001c0
VISUAL cropResistant
28280c08284c4c30

Code Analysis

Risk Score 50/100
Threat Level ALTO
āš ļø Phishing Confirmed
šŸŽ£ Personal Info

šŸ”¬ Threat Analysis Report

• Threat: Phishing
• Target: Unsuspecting users
• Method: Credential harvesting
• Exfil: https://digitalnomad.saithaimio.enterprises/k2mCBPyx3AEP!FU8T/$
• Indicators: Suspicious form action, generic design.
• Risk: HIGH

šŸ” Credential Harvesting Forms

šŸ“¤ Form Action Targets

  • https://digitalnomad.saithaimio.enterprises/k2mCBPyx3AEP!FU8T/$

šŸ“Š Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Suspicious Form Action
The form submits data to a URL that does not belong to the gts.com.uy domain.
Generic Branding
The page lacks specific branding and appears generic.
Requesting Sensitive Information
The page asks for email address, increasing the chance of fraudulent activity.

šŸ”¬ Comprehensive Threat Analysis

Threat Type
Phishing Kit (Personal Info)
Target
General public
Attack Method
credential harvesting forms
Exfiltration Channel
HTTP POST to backend
Risk Assessment
MEDIUM - Automated credential harvesting with HTTP POST to backend

āš ļø Indicators of Compromise

  • Kit types: Personal Info

šŸ¢ Brand Impersonation Analysis

Impersonated Brand
Secure Document Portal (Generic)
Fake Service
Document Access

Fraudulent Claims

āš”ļø Attack Methodology

Primary Method: Credential Harvesting

The attacker attempts to steal user credentials (email) by impersonating a secure document access portal.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
gts.com.uy
Registered
Unknown
Registrar
Unknown
Status
Active

šŸ¤– AI-Extracted Threat Intelligence

Scan History for gts.com.uy

Found 2 other scans for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.