EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

http://dev.catchrecording.cefasext.co.uk
Detected Brand
GOV.UK
Country
UK
Confidence
95%
HTTP Status
200
Report ID
a59006a3-231…
Analyzed
2025-12-21 16:18
Final URL (after redirects)
https://dev.catchrecording.cefasext.co.uk/sign-in

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1C40428C366956F7B8A3204CA888C72A3B74FE1FDE5900370567C90EF13DB95AF55A086
CONTENT ssdeep
3072:BLWf/0ZLLcESHotgzCmKrH1dwuHPnBdnk4:wwJSHimKz1dwuvrk4

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9a56475f164b161e
VISUAL aHash
00fffffffffffbff
VISUAL dHash
693630383030121a
VISUAL wHash
00cfcfcfdfdf0000
VISUAL colorHash
070000003c0
VISUAL cropResistant
00943c4c00209060,1a2018383032121a,6969696969444896

Code Analysis

Risk Score 100/100
Threat Level ALTO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing targeting GOV.UK users.
• Target: Individuals trying to access a GOV.UK service.
• Method: Fake login page prompting for email address and password.
• Exfil: Likely sent to an attacker-controlled server.
• Indicators: Domain mismatch (dev.catchrecording.cefasext.co.uk vs gov.uk).
• Risk: HIGH - Risk of stolen credentials leading to unauthorized access to government services.

🔐 Credential Harvesting Forms

📡 API Calls Detected

  • POST
  • GET
  • https://www.google.com/ccm/geo

📤 Form Action Targets

  • services/signin
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.