EN ES PT
Back to Stats

Visual Capture

Screenshot of assauao-kdtasewp8q.edgeone.app

Detection Info

http://assauao-kdtasewp8q.edgeone.app/goodnew0usaa.html
Detected Brand
USAA
Country
USA
Confidence
100%
HTTP Status
200
Report ID
a592edc9-6dfโ€ฆ
Analyzed
2026-03-15 22:24
Final URL (after redirects)
https://assauao-kdtasewp8q.edgeone.app/goodnew0usaa.html

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T193A2326311049D371886CAF86BF9FF2A36528767DB854201D2E823ED0BEEDD0DE15794
CONTENT ssdeep
384:FU8i5iul09aWECcthMILmfiFfxbOeagnURY9S2CKEOeagnUCYyI2CnOeagnURYF2:ri5iul0sWCZrD8gDlOAvWqRvQ

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
ff807f807f2a6850
VISUAL aHash
00ffffffffffff00
VISUAL dHash
7380414900000000
VISUAL wHash
00ff01efffff0000
VISUAL colorHash
07040000180
VISUAL cropResistant
a800510900000000,8040404041434380,100010b210959595,0040400000004000

Code Analysis

Risk Score 100/100
Threat Level ALTO
โš ๏ธ Phishing Confirmed
๐ŸŽฃ Credential Harvester ๐ŸŽฃ OTP Stealer ๐ŸŽฃ Card Stealer ๐ŸŽฃ Banking ๐ŸŽฃ Personal Info
Telegram Exfiltration

๐Ÿ”ฌ Threat Analysis Report

โ€ข Threat: Phishing
โ€ข Target: USAA customers
โ€ข Method: Impersonation via malicious domain.
โ€ข Exfil: Telegram Bots
โ€ข Indicators: Malicious domain, JavaScript obfuscation, form submission.
โ€ข Risk: High

๐Ÿ”’ Obfuscation Detected

  • unescape
  • document.write
  • unicode_escape

๐ŸŽฏ Kit Endpoints

  • https://www.usaa.com/my/logon
  • https://www.usaa.com/inet/wc/security_center?0&wa_ref=logon_jump_security_center

๐Ÿ“ก API Calls Detected

  • post
  • GET

๐Ÿ”‘ Telegram Bot Tokens (2)

  • 1750418914:AAGv...yC3JCLPM
  • 5167651471:AAGV...OSJnhbJ0

๐Ÿ’ฌ Telegram Chat IDs (2)

  • 2128570674
  • -1001403579854

๐Ÿ“Š Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Malicious Domain
The domain is not a legitimate USAA domain.
JavaScript Obfuscation
Obfuscation is used to hide malicious code.
Telegram Token
The site likely has malicious intentions due to having tokens used for Telegram bots.
Form Submission
The site has a form used for data harvesting.

๐Ÿ”ฌ Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
USAA users (USA)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Telegram Bot (1750418914:AAGvauViE...)
Risk Assessment
CRITICAL - Automated credential harvesting with Telegram Bot (1750418914:AAGvauViE...)

โš ๏ธ Indicators of Compromise

  • 2 Telegram bot token(s)
  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 8 obfuscation techniques

๐Ÿข Brand Impersonation Analysis

Impersonated Brand
USAA
Official Website
usaa.com
Fake Service
Login

โš”๏ธ Attack Methodology

Primary Method: Credential Harvesting

The attacker is using a fake login page to steal USAA customer's Online IDs.

Secondary Method: Data Exfiltration via Telegram Bots

Stolen credentials and potential data are sent to a remote server, potentially controlled by the attacker via Telegram bots using the extracted tokens.

๐Ÿ“ก Telegram Command & Control Infrastructure

Bot Token (Masked)
1750418914:AAGv...yC3JCLPM
Bot ID
1750418914
Group/Chat ID
2128570674
Operator Language
Unknown

๐Ÿ’ฌ Message Templates (3)

ID Portuguese English Trigger

๐ŸŒ Infrastructure Indicators of Compromise

Domain Information

Domain
assauao-kdtasewp8q.edgeone.app
Registered
None
Registrar
None
Status
Inactive

๐Ÿค– AI-Extracted Threat Intelligence

๐Ÿ˜ฐ
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.