EN ES PT
Back to Stats
92 Risk Score

High Risk

Threat Level: BAJO • Impersonating: Tax Relief USA
  • • Threat: Potential data collection for marketing purposes.
  • • Target: Individuals with tax debt in the USA.
  • • Method: Form collects information about tax debt to determine eligibility for relief programs.
  • • Exfil: Unknown, likely a database for lead generation.
  • • Indicators: Legitimate looking site, but data collection practices may be aggressive.
  • • Risk: LOW - Data collection, but likely not credential theft.

⚠ Risk Factors

  • Credential harvesting indicators detected
  • OTP/2FA stealing indicators detected

Visual Capture

No screenshot available

Detection Info

https://www.taxreliefamerica.org/lo?campaign_id=461778&aff_id=562077&ad_id=0&aff_sub=821908&click_id=01_204769928_17059717-18fb-46d7-9509-c7d2e899f68a&AffiliateReferenceID=747882496
Detected Brand
Tax Relief USA
Country
USA
Confidence
100%
HTTP Status
200
Report ID
9bf9f126-746…
Analyzed
2026-01-11 05:02

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1BA635CE8F500F523967300D770AF1952B339561BEA0E0950F36CEEDA67F48566137ACA
CONTENT ssdeep
768:Cgfk/z2q7LU7WVzDF1MUxBLXPTT2S6Mq6zTCGE3BfrTP+Q4cnjMGI9Uf4zX//gyy:GzDfMGL7yW7IB3qcnze//dQV

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9212e8ec6cece19e
VISUAL aHash
ff0c0c0000ffffff
VISUAL dHash
3cd8f8fc6d060c16
VISUAL wHash
170c0c0000ffffff
VISUAL colorHash
060000001c0
VISUAL cropResistant
00202028282400b4,d8f8f8ec66060c16,f8d878d8f8fcec6c

Code Analysis

Risk Score 92/100
Threat Level BAJO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Potential data collection for marketing purposes.
• Target: Individuals with tax debt in the USA.
• Method: Form collects information about tax debt to determine eligibility for relief programs.
• Exfil: Unknown, likely a database for lead generation.
• Indicators: Legitimate looking site, but data collection practices may be aggressive.
• Risk: LOW - Data collection, but likely not credential theft.

🔒 Obfuscation Detected

  • atob
  • fromCharCode
  • hex_escape
  • base64_strings