EN ES PT
Back to Stats

Visual Capture

Screenshot of ansaruchtlknt.com

Detection Info

https://ansaruchtlknt.com/bh/LINK/FILE/cc/NRD/8c6ea43/Account/Account.php
Detected Brand
Nordea
Country
International
Confidence
95%
HTTP Status
200
Report ID
ba89f8bf-ad5…
Analyzed
2026-01-17 01:58

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1D2D2CA1051081A3B058743DCE3EB67F6739ED288CE12429926F9C778DFE7CA4DD4A2A5
CONTENT ssdeep
384:Ue+qmV6zifNCX6CD3Bl74BjnP04MO2wlr5piyK3q8otPIkfULHkmKHOa:P+qmV6ziMX6CD3z6VZ2wlrZ8IP3SkRf

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9c1c1859737366e6
VISUAL aHash
0018ffffffffffff
VISUAL dHash
b0b20c2830080000
VISUAL wHash
000017071f0f0f0f
VISUAL colorHash
0e006000000
VISUAL cropResistant
b22ca83224080000,aab6b28cb2b2b2b2

Code Analysis

Risk Score 65/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester

🔬 Threat Analysis Report

• Threat: Banking credential phishing
• Target: Nordea Netbank users
• Method: Fake login page attempting to steal PIN or biometric data
• Exfil: Data likely sent to attacker-controlled server or Telegram bot
• Indicators: Newly registered domain, unusual domain name, obfuscated JavaScript, multiple forms
• Risk: HIGH - Potential credential theft and unauthorized access to banking accounts

🔒 Obfuscation Detected

  • fromCharCode

📡 API Calls Detected

  • GET
  • ./System_sql/Redirect.txt
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.