EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

https://www.flowcode.com/page/attpaymentupodate
Detected Brand
AT&T
Country
USA
Confidence
100%
HTTP Status
200
Report ID
f7ac5d53-d90…
Analyzed
2026-01-01 03:16
Final URL (after redirects)
https://www.flow.page/attpaymentupodate

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1045295F662C1AD2B932331D8F1D2F7CEF043620EDAC94A84B5BE07F552DACB64015969
CONTENT ssdeep
384:Hw1FRo+1H1pd/cB3B7PdyC9N9FXWKeWaGoCggYCCgtNC33:Hw1voQH1ncNdoSNSGFYgNC3

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
aa35ca35ca35ca35
VISUAL aHash
00000000000000ff
VISUAL dHash
0e0e091e1b1f1ec9
VISUAL wHash
03070b0f0f0f0fff
VISUAL colorHash
00007000000
VISUAL cropResistant
8d00c9c109c980c9,0e0e091f131b120f

Code Analysis

Risk Score 95/100
Threat Level BAJO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Potential billing update scam - redirected via QR code service
• Target: AT&T customers in the USA
• Method: Requests users to verify billing information after being redirected from a QR code scan
• Exfil: Unknown; potential data harvesting via fake billing form
• Indicators: AT&T branding, request for billing verification, redirection from flowcode.com
• Risk: LOW - Requires user interaction, potential for credential theft if malicious link is used

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • hex_escape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • https://flow.page/privacy-policy#notice-at-collection

📡 API Calls Detected

  • GET
  • /api/social-validation/youtube?handle=
  • POST
  • /api/social-validation/facebook?handle=
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.