EN ES PT
Back to Stats

Visual Capture

Screenshot of virginmedia.effective-software.com

Detection Info

https://virginmedia.effective-software.com/login
Detected Brand
Virgin Media
Country
UK
Confidence
100%
HTTP Status
200
Report ID
db692d86-88e…
Analyzed
2026-03-02 13:41

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T15881753170249C26C202CDE8A2D1DB26A2878351C7866D24F5F08A5D7BDBCD0D679DBE
CONTENT ssdeep
48:TcKthPyvRl+xJXEKYrHJKJVaTzvJqL/aPYJHgZzo6hjxp5GHp6n15kEuBlI+0:T9wy6Ho2TEjHanB5GHp6n15kEuBlIR

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
889db63217983377
VISUAL aHash
1c1c18181841c1c1
VISUAL dHash
b0b0b2b2b38f8707
VISUAL wHash
1e1c185879e3e3e3
VISUAL colorHash
00000000006
VISUAL cropResistant
f8b1b989e9816919,fefcfcf8f0f0e0c0,28b0d6dedeefffff,b0b0b2b2b38f8707

Code Analysis

Risk Score 95/100
Threat Level ALTO
āš ļø Phishing Confirmed
šŸŽ£ Credential Harvester šŸŽ£ OTP Stealer šŸŽ£ Banking šŸŽ£ Personal Info

šŸ”¬ Threat Analysis Report

• Threat: Credential Phishing
• Target: Virgin Media customers
• Method: Impersonation of login page.
• Exfil: JavaScript with obfuscation likely attempts to steal credentials.
• Indicators: Domain mismatch, presence of login form.
• Risk: HIGH

šŸ”’ Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • document.write
  • hex_escape
  • unicode_escape
  • base64_strings

šŸ“” API Calls Detected

  • ^
  • ~
  • https://cuan.effective-software.com/login
  • _
  • POST
  • https://virginmedia.effective-software.com/login
  • https://virginmedia.effective-software.com/ajax/session.php
  • PUT

šŸ“Š Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain Mismatch
The domain does not belong to the brand.
Credential Harvesting
The page has a login form, asking for sensitive data.
Obfuscated Javascript
Javascript is obfuscated and likely contains malicious code to steal the credetials.

šŸ”¬ Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Virgin Media users (UK)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

āš ļø Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 77 obfuscation techniques

šŸ¢ Brand Impersonation Analysis

Impersonated Brand
Virgin Media
Official Website
virginmedia.com
Fake Service
Login Portal

āš”ļø Attack Methodology

Primary Method: Credential Harvesting

The attacker attempts to steal user credentials by creating a fake login page that mimics the appearance of the Virgin Media login. The user is tricked into entering their email and password.

Secondary Method: Javascript Obfuscation

The JavaScript code is obfuscated to make it difficult to analyze and detect malicious activity such as credential theft and data exfiltration.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
virginmedia.effective-software.com
Registered
2013-03-16
Registrar
Unknown
Status
Active

šŸ¤– AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.