EN ES PT
Back to Stats

Visual Capture

Screenshot of extpaypalupdatenonqs.blogspot.com

Detection Info

https://extpaypalupdatenonqs.blogspot.com/2021/02
Detected Brand
PayPal
Country
International
Confidence
100%
HTTP Status
200
Report ID
efd61a7b-8e8…
Analyzed
2026-01-01 09:50

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T15D5220B29485D93B5363C6E9B3B1A74BFB81C189C886014AE5F5D35C1FE3DB2EC0A215
CONTENT ssdeep
96:j58HUZnoGyPFmGjZz/0/HrJSEmwh2FwGgjP2jHu+pafjztBkXejaE6SindVDJ9D7:j5kUCFMOuNSEGwt+UgjfDJep9ZTsrUJU

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
de7e61a1a19e9e80
VISUAL aHash
80809c9cffffffff
VISUAL dHash
2822343003202024
VISUAL wHash
80809c80cfcfcfc7
VISUAL colorHash
07007000000
VISUAL cropResistant
2822343003202024,0090f006e0e0e0e8

Code Analysis

Risk Score 89/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Brand impersonation phishing using a free hosting service.
• Target: PayPal users are targeted.
• Method: The phishing page uses the PayPal logo and branding but is hosted on a blogspot domain, likely leading to a form for credential theft.
• Exfil: The form action points to the blogspot domain, suggesting data exfiltration through a custom script or similar method.
• Indicators: Free hosting, domain mismatch, brand impersonation, obfuscation detected.
• Risk: HIGH - Credential theft and potential account compromise.

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • eval
  • hex_escape
  • unicode_escape

🎯 Kit Endpoints

  • https://www.blogger.com/share-post.g?blogID=4165901018681820242&postID=8043106242831253549&target=twitter
  • https://www.blogger.com/profile/11377455202849998003
  • https://www.blogger.com/share-post.g?blogID=4165901018681820242&postID=8043106242831253549&target=email
  • https://extpaypalupdatenonqs.blogspot.com/feeds/posts/default?alt=rss
  • https://www.blogger.com
  • https://extpaypalupdatenonqs.blogspot.com/feeds/posts/default
  • https://extpaypalupdatenonqs.blogspot.com/2021/02/blog-post.html#comments
  • https://www.blogger.com/share-post.g?blogID=4165901018681820242&postID=8043106242831253549&target=
  • https://extpaypalupdatenonqs.blogspot.com/
  • /responsive/sprite_v1_6.css.svg#ic_post_blogger_black_24dp
  • https://www.blogger.com/share-post.g?blogID=4165901018681820242&postID=8043106242831253549&target=facebook
  • https://extpaypalupdatenonqs.blogspot.com/2021/02/
  • https://www.blogger.com/go/report-abuse
  • https://www.blogger.com/share-post.g?blogID=4165901018681820242&postID=8043106242831253549&target=pinterest
  • https://extpaypalupdatenonqs.blogspot.com/2021/02/blog-post.html
  • https://extpaypalupdatenonqs.blogspot.com/search
  • https://www.blogger.com/feeds/4165901018681820242/posts/default

📡 API Calls Detected

  • GET
  • post

📤 Form Action Targets

  • https://extpaypalupdatenonqs.blogspot.com/search
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.