EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

https://mondialrelayy.cloudaccess.host/captcha.php
Detected Brand
Unknown
Country
Unknown
Confidence
75%
HTTP Status
200
Report ID
f44fdafa-150…
Analyzed
2026-01-25 02:39

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T15F21DC71111869B32582E2D96176F78FF2C28205EB872344E6F1D3DE9BDEC94CC096C0
CONTENT ssdeep
24:n/CbrDfJACfZhgbbCW7Yp2eQxPgJ7HAzzM:nWvxhRe/Clp2eQxP0HAzzM

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b366cc9932663399
VISUAL aHash
ffffe7e7efefffff
VISUAL dHash
8d224c4d595e6295
VISUAL wHash
07070707071f3f3f
VISUAL colorHash
07000000007
VISUAL cropResistant
8d224c4d595e6295,4040a2d8c820c0c0

Code Analysis

Risk Score 53/100
🎣 OTP Stealer

🔒 Obfuscation Detected

  • base64_strings

📡 API Calls Detected

  • set_captcha_validated.php

🔬 Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
General public
Attack Method
obfuscated JavaScript
Exfiltration Channel
Unknown
Risk Assessment
MEDIUM - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer
  • 1 obfuscation techniques

⚔️ Attack Methodology

Primary Method: OTP Interception

The phishing kit employs an OTP stealer to capture one-time passwords sent via SMS or authenticator apps. Victims are tricked into entering OTPs on the fake page, which are then forwarded to the attacker in real-time for immediate account takeover.

Secondary Method: Credential Harvesting

Alongside OTP interception, the kit captures usernames and passwords entered by victims. These credentials are likely stored or exfiltrated for later use in unauthorized access to accounts.

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.