EN ES PT
Back to Stats

Visual Capture

Screenshot of www.proxypush.com

Detection Info

https://www.proxypush.com/evote/RHC/login
Detected Brand
Robinhood
Country
USA
Confidence
100%
HTTP Status
200
Report ID
ed1cba01-699…
Analyzed
2026-01-01 21:58

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1AAE1B770A454693741E2C1D9F3F9E306D296C249C61A2C42B7F88BEE0FE3D25D863796
CONTENT ssdeep
96:HE1KcvXl478K2s67vi4oseiZPSpY7fRdXtvb99G38p:XMC/wbos3cYlIA

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
a7a30d8b07a70d9d
VISUAL aHash
ffffffffffffff00
VISUAL dHash
c00c0c0c08100094
VISUAL wHash
3f000327243cbd00
VISUAL colorHash
07000000c00
VISUAL cropResistant
d00c040c0c000000,0084d41400303000

Code Analysis

Risk Score 73/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 Banking

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing targeting Robinhood customers
• Target: Robinhood users
• Method: Fake login form asking for a 'control number' likely used in proxy voting scenarios. This 'control number' could be a credential or provide access to voting details and thus compromise user accounts and voting data.
• Exfil: Form data posted to /evote/RHC/logout or /evote/RHC/auth
• Indicators: Domain mismatch (proxypush.com vs robinhood.com), unusual form actions, obfuscated javascript
• Risk: HIGH - Potential account compromise and data theft

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • fromCharCode

📡 API Calls Detected

  • GET

📤 Form Action Targets

  • /evote/RHC/logout
  • /evote/RHC/auth

Scan History for www.proxypush.com

Found 1 other scan for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.