EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

http://crq4804.na1.hubspotlinks.com/Btc/U+113/cRq4804/VX80ZN54KNB5N4kS8rFkQBhCW1sXT7r4xspJdM7WCRp3pl2SV1-WJV7CgCwCW2h3Kln47Mk7mN4X7whKxrN5KW1vlGC94nYh6SW85_p586Jxb-jW5kWxsm81NR3qW72fZdq7D_fzkV9s24c9fs35TN61-8RxKl-hSW5dyyNH1wXMrYVbCYjM2stV4LN1VMV2WZ4XfWW3vzhLv5t2SFRW8gFbp77bM-fbW8tT6Jq8jSD3MVTGk_B5Mm2_rW82pyKS8s6nBCN29D51Qw_DlnW3h_hkR89rTbzW2-FQXk8cLmWgW57lJDJ8B96mwV4MKVQ2T3DB8W90tzD-3Tj7gtW942BH46tmFhhW7M1QVh5-tqqZ3prB1
Detected Brand
Facebook
Country
International
Confidence
95%
HTTP Status
200
Report ID
e6928f9e-84f…
Analyzed
2025-12-21 13:38
Final URL (after redirects)
https://www.facebook.com/login/?next=https%3A%2F%2Fwww.facebook.com%2Fimployablebiz%3Futm_campaign%3DMonthly%2BE-Newsletters%26utm_medium%3Demail%26_hsenc%3Dp2ANqtz-8Zeeh8Eon8-dPKofxwv6RRgOiUqETQ2ZPBcJbvr-QDy1b62bexyqN-lUWXto-NjetUvGrCxyAMOA6gRSCnWbxUpaAXnw%26_hsmi%3D159378811%26utm_content%3D159378811%26utm_source%3Dhs_email

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1B723C7259209B0620B7B4FF4A87E41171297995FF8B2A0A09D36F7E634D3FF5AD5E008
CONTENT ssdeep
1536:pPty6KZQD9xJ0hhOBsa8FHqqZjispgNmzUmKE+GnIWnIjiD99jifIAaiqgcukcOR:4FHqqZjispgNmzUmKE+GnIWnIjiD99jr

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b372ce8158ce8cbc
VISUAL aHash
efe7c7c4476fffff
VISUAL dHash
8c0f9d099dd9ce36
VISUAL wHash
67c7c0c0454f6fc3
VISUAL colorHash
07202000040
VISUAL cropResistant
8c0f9d099dd9ce36,3c3c19535efd7d7d,e86233339b8d978e,0008303232100800,72cfe7e3e3642599

Code Analysis

Risk Score 70/100
Threat Level ALTO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Facebook credential phishing
• Target: Facebook users
• Method: Fake Facebook login page to steal credentials
• Exfil: Likely to a remote server controlled by the attacker
• Indicators: Domain mismatch, use of HubSpot links, Facebook branding
• Risk: HIGH - Immediate credential theft

🎯 Kit Endpoints

  • https://l.facebook.com/l.php?u=https%3A%2F%2Fwww.meta.ai%2Fpages%2Fkitchen-sink-trends-seamless-designs-sustainable-materials-smart-technology%2F%3Futm_source%3Dfoa_web_footer&h=AT2DchPAeT4pugcD9FsK9XWk7Uf_HeokfI4bWsawvAYmcMkK7BvB_IiErocrEuThB91G7Hd6Ezk2hA1UKT5ihyhmexQVwkTq9NfhBCaZzkmEurUfRcwdxraPZqyo3mq_aAVJTdgdwGuLx9SXw-EuLw
  • https://www.facebook.com/recover/initiate/?privacy_mutation_token=eyJ0eXBlIjo1LCJjcmVhdGlvbl90aW1lIjoxNzY2MzI0MjU2fQ%3D%3D&ars=facebook_login&next=https%3A%2F%2Fwww.facebook.com%2Fimployablebiz%3Futm_campaign%3DMonthly%2BE-Newsletters%26utm_medium%3Demail%26_hsenc%3Dp2ANqtz-8Zeeh8Eon8-dPKofxwv6RRgOiUqETQ2ZPBcJbvr-QDy1b62bexyqN-lUWXto-NjetUvGrCxyAMOA6gRSCnWbxUpaAXnw%26_hsmi%3D159378811%26utm_content%3D159378811%26utm_source%3Dhs_email
  • /reg/?entry_point=login&next=https%3A%2F%2Fwww.facebook.com%2Fimployablebiz%3Futm_campaign%3DMonthly%2BE-Newsletters%26utm_medium%3Demail%26_hsenc%3Dp2ANqtz-8Zeeh8Eon8-dPKofxwv6RRgOiUqETQ2ZPBcJbvr-QDy1b62bexyqN-lUWXto-NjetUvGrCxyAMOA6gRSCnWbxUpaAXnw%26_hsmi%3D159378811%26utm_content%3D159378811%26utm_source%3Dhs_email
  • https://l.facebook.com/l.php?u=https%3A%2F%2Fabout.meta.com%2Ftechnologies%2Fmeta-pay&h=AT2DchPAeT4pugcD9FsK9XWk7Uf_HeokfI4bWsawvAYmcMkK7BvB_IiErocrEuThB91G7Hd6Ezk2hA1UKT5ihyhmexQVwkTq9NfhBCaZzkmEurUfRcwdxraPZqyo3mq_aAVJTdgdwGuLx9SXw-EuLw
  • https://www.facebook.com/login/

📡 API Calls Detected

  • GET
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.