EN ES PT
Back to Stats

Visual Capture

Screenshot of www.eatskorea.com

Detection Info

https://www.eatskorea.com/vander/20/loading/banklist.php?phone=0212228900
Detected Brand
Inland Revenue (New Zealand)
Country
Unknown
Confidence
100%
HTTP Status
200
Report ID
cc06b14e-ccf…
Analyzed
2026-03-20 03:24

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T148F18332A888A93B41C757E8F7723B6933F58344C61B0605DAEC83FD5B9AE85CD135A4
CONTENT ssdeep
192:Px8CmdTLAhYhM6EeLqrO0WEUiNUTAgEAS1o:abLtM6/LqrO0/EAXK

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c7326930c76d328f
VISUAL aHash
00003e3e3e343838
VISUAL dHash
92646c6c686c6362
VISUAL wHash
003e3e3e3e3e3878
VISUAL colorHash
02001000180
VISUAL cropResistant
92e29a8a8c8e888e,aa805abae2c0b4a0,92646c6c686c6362

Code Analysis

Risk Score 75/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer
Telegram Exfiltration

🔑 Telegram Bot Tokens (1)

  • 8760774390:AAFt...t2G40uGg

📊 Risk Score Breakdown

Total Risk Score
75/100

Contributing Factors

Active Phishing Kit
Detected kit types: OTP Stealer
Telegram Exfiltration
Real-time data exfiltration via Telegram (1 bot token(s) exposed in client-side code)

🔬 Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
Inland Revenue (New Zealand) users
Attack Method
Phishing webpage
Exfiltration Channel
Telegram Bot (8760774390:AAFtwULOz...)
Risk Assessment
HIGH - Automated credential harvesting with Telegram Bot (8760774390:AAFtwULOz...)

⚠️ Indicators of Compromise

  • 1 Telegram bot token(s)
  • Kit types: OTP Stealer

🏢 Brand Impersonation Analysis

Impersonated Brand
Inland Revenue (New Zealand)
Official Website
N/A
Fake Service
Credential harvesting service

⚔️ Attack Methodology

Primary Method: Two-Factor Authentication Bypass

Victim is prompted for 2FA code after entering credentials. The code is intercepted and used by attacker to access victim's account in real-time.

Secondary Method: Standard Phishing Techniques

Uses typical phishing tactics including brand impersonation, urgency tactics, and social engineering to trick victims into providing sensitive information.

📡 Telegram Command & Control Infrastructure

Bot Token (Masked)
8760774390:AAFt...t2G40uGg
Bot ID
8760774390
Group/Chat ID
Unknown
Operator Language
Unknown

💬 Message Templates (3)

ID Portuguese English Trigger

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
www.eatskorea.com
Registered
2024-07-08 01:25:01+00:00
Registrar
Gabia, Inc.
Status
Active (older domain)

Hosting Information

Provider
Gabia, Inc.
ASN

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.