EN ES PT
Back to Stats
100 Risk Score

High Risk

Threat Level: ALTO • Impersonating: Galicia

⚠ Factores de Riesgo

  • Contiene 1 token(s) de bot Telegram para exfiltración de credenciales
  • Contiene 1 formulario(s) con envío JavaScript
  • Ofuscación JavaScript detectada (5 patrones)
  • Indicadores de robo de credenciales detectados
  • Indicadores de robo de otp/2fa detectados

Visual Capture

Screenshot of galiciaonline.z14.web.core.windows.net

Detection Info

https://galiciaonline.z14.web.core.windows.net/
Detected Brand
Galicia
Country
Unknown
Confidence
100%
HTTP Status
200
Report ID
6524be25-047…
Analyzed
2026-01-09 03:04

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T138E16478B1E007B761D787B7B291EF25A9EDC747DA63D9A6F2E4C24A02DDC50DD02280
CONTENT ssdeep
96:VdZWEBJDTzuCsO1ZzuCh1hzuC/zEi0TseCm1shJ7GmBPJ/F0KOuzvkUTpV8+:VdZWIJhJdJ4MeCm1s7SiPRFOuzxb

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c996a50ba5abada8
VISUAL aHash
f8f8f8f8f8f8f8f8
VISUAL dHash
d290313333131313
VISUAL wHash
78d8f898c8d8f8d8
VISUAL colorHash
07c00010000
VISUAL cropResistant
d290313333131313,8b1529186b6d5dd7,1df17dac9bb72e6b,658ccb3355cb2636

Code Analysis

Risk Score 100/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Personal Info
Telegram Exfiltration

🔒 Obfuscation Detected

  • atob
  • fromCharCode
  • unicode_escape
  • js_packer
  • base64_strings

🔑 Telegram Bot Tokens (1)

  • 8426370078:AAHD...qS80LjFw

Scan History for galiciaonline.z14.web.core.windows.net

Found 1 other scan for this domain