EN ES PT
Back to Stats

Visual Capture

Screenshot of tesla.demo.webernets.online

Detection Info

https://tesla.demo.webernets.online
Detected Brand
Outlook
Country
International
Confidence
100%
HTTP Status
200
Report ID
6570b609-07d…
Analyzed
2026-01-04 01:52
Final URL (after redirects)
https://tesla.demo.webernets.online/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T13E51E2A0D055AC335103E2E867E4AB8B3687C715C687290953F0C3AC2EF3C4DDF66669
CONTENT ssdeep
48:CVhhzJzZyd9CPTOVyUhxnja26YXAPy9uilLM7aynBLP5ut16:uLzZyGPKhxnebBy9ui9MeSFxu6

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
83e67f0103039bfe
VISUAL aHash
3f3f3f3f3f3f3f3f
VISUAL dHash
d0c6ccd8d0d0d0d0
VISUAL wHash
3f233f3f3f0f0000
VISUAL colorHash
060000001c0
VISUAL cropResistant
808c9890a0808080,f184acb6b6ac84f3,0e71710e20000000

Code Analysis

Risk Score 58/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing attack targeting Outlook users.
• Target: Outlook users.
• Method: A fake Outlook login page is presented to steal usernames and passwords.
• Exfil: Data is likely being sent to https://webernets.online/owa/auth.owa based on form action.
• Indicators: Domain mismatch (tesla.demo.webernets.online vs. outlook.live.com), document.write obfuscation, JavaScript form submission.
• Risk: HIGH - Real-time credential theft is possible.

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • document.write

📤 Form Action Targets

  • https://webernets.online/owa/auth.owa

Scan History for tesla.demo.webernets.online

Found 1 other scan for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.