EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

http://admin-form-fn-prod-ods.insolvency-development.co.uk
Detected Brand
GOV.UK
Country
UK
Confidence
95%
HTTP Status
200
Report ID
eab8c0e4-2c3…
Analyzed
2025-12-20 17:46
Final URL (after redirects)
https://admin-form-fn-prod-ods.insolvency-development.co.uk/Account/Login?ReturnUrl=%2F

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T16DD18435A4155C2A0713EBC5F3A2737AD183C249C7960D04E5FC47AE0BEAEA5C89A327
CONTENT ssdeep
96:Ws0lGTGiSGvRGmGmIKWGlHtCrFzbX2BRGxR6Eko4XPFssWZC0myJ:WsysnS6RfRWKHSofMR6EkHa

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
bc34636167366963
VISUAL aHash
00ffffff0000ffff
VISUAL dHash
1e003020223a0400
VISUAL wHash
00ffdfdf0000c0ff
VISUAL colorHash
070000003c0
VISUAL cropResistant
3a203228323a0c00,403048484a489616

Code Analysis

Risk Score 70/100
Threat Level ALTO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing attack
• Target: Users of GOV.UK services, particularly those related to insolvency.
• Method: Fake login form steals username and password.
• Exfil: Unknown, likely to a server controlled by the attacker.
• Indicators: Domain name impersonating an aspect of Insolvency Service, username/password fields, generic login page.
• Risk: HIGH - Immediate credential theft.

🔐 Credential Harvesting Forms

🎯 Kit Endpoints

  • /Account/Login?ReturnUrl=%2F

📤 Form Action Targets

  • /Account/Login?ReturnUrl=%2F
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.