EN ES PT
Back to Stats

Captura Visual

No screenshot available

Informações de Detecção

http://dev.catchrecording.cefasext.co.uk
Detected Brand
GOV.UK
Country
UK
Confiança
100%
HTTP Status
200
Report ID
f3bc6cd2-d30…
Analyzed
2025-12-23 20:38
Final URL (after redirects)
https://dev.catchrecording.cefasext.co.uk/sign-in

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1C40428C366956F7B8A3204CA888C72A3B74FE1FDE5900370567C90EF13DB95AF55A086
CONTENT ssdeep
3072:BLWf/0ZLLcESHotgzCmKrH1dwuHPnBdnk4:wwJSHimKz1dwuvrk4

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9a56475f164b161e
VISUAL aHash
00fffffffffffbff
VISUAL dHash
693630383030121a
VISUAL wHash
00cfcfcfdfdf0000
VISUAL colorHash
070000003c0
VISUAL cropResistant
00943c4c00209060,1a2018383032121a,6969696969444896

Análise de Código

Risk Score 100/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing targeting GOV.UK users.
• Target: Users attempting to access a GOV.UK service.
• Method: Presents a fake login page to steal email and password.
• Exfil: The destination where stolen credentials are sent is unknown but presumed to be a remote server controlled by the attackers.
• Indicators: Domain name does not match the official GOV.UK domain, contains 'dev', 'catchrecording', 'cefasext'. The URL is likely a subdomain or a misconfigured testing environment.
• Risk: HIGH - Immediate credential theft.

🔐 Credential Harvesting Forms

📡 API Calls Detected

  • POST
  • GET
  • https://www.google.com/ccm/geo

📤 Form Action Targets

  • services/signin
😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.