EN ES PT
Back to Stats

Visual Capture

Screenshot of www.elegant-khorana.45-83-245-57.plesk.page

Detection Info

https://www.elegant-khorana.45-83-245-57.plesk.page
Detected Brand
Plesk
Country
Unknown
Confidence
100%
HTTP Status
200
Report ID
6e02240d-e51…
Analyzed
2026-01-05 07:16
Final URL (after redirects)
https://www.elegant-khorana.45-83-245-57.plesk.page/login_up.php

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T11602FC32644CED3B23235FD17492B705E2D6C66ECA421610D6B8439E0FFBEE2E44665B
CONTENT ssdeep
192:AHmJ6kYMHSTCuCgEESzqCNtBdDxe8L+jKkrfjg1r9j3rr7dv:ymJ6kR+3jWqCNFxe8L+jKkrfjg1r9j3F

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
cc6666cd4c763233
VISUAL aHash
0018001818181800
VISUAL dHash
62724cb2b2b2b24c
VISUAL wHash
0018ffff38383c3c
VISUAL colorHash
070060000c0
VISUAL cropResistant
acb2e280333398ba,62724cb2b2b2b24c

Code Analysis

Risk Score 95/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • document.write
  • hex_escape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • https://support.plesk.com/hc/en-us/articles/12377667582743-How-to-log-in-to-Plesk-
  • log-in
  • /login_up.php?modals[cookie-policy-preferences]=true
  • ${(0,m.default)(`/admin/report/download/file/${encodeURIComponent(n.file)}`)}

📡 API Calls Detected

  • /modules/notifier/index.php/notifications
  • GET
  • https://o447951.ingest.sentry.io/api/4509632503087104/envelope/?sentry_version=7&sentry_key=c1dfb07d783ad5325c245c1fd3725390&sentry_client=sentry.javascript.browser%2F1.33.7
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.