EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

http://nemo89.net/
Detected Brand
Nemo89
Country
International
Confidence
100%
HTTP Status
200
Report ID
6e53e4e0-3dd…
Analyzed
2026-03-11 04:26
Final URL (after redirects)
https://nemo89.net/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T10C730F22680E052FB157D7C5A1F4FAA7DD91CD0ADE300F40EAA5EFCACA91F11B675218
CONTENT ssdeep
768:Yhd5kOB4VmXHd5FbrPvhJLOSmukKukoQXOA0T80+Wyidm7:c5V4Vfm7

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b3b14454aaceb693
VISUAL aHash
0006ffff0f000000
VISUAL dHash
d49adb9bdb5c481b
VISUAL wHash
000fffff0f073c01
VISUAL colorHash
39400018000
VISUAL cropResistant
8acc9d8496969684,55556a2b9dba3353,6766646e6a6a0a8a,d49adb9bdb5c481b

Code Analysis

Risk Score 79/100
Threat Level BAJO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Gambling Website
• Target: Gamblers
• Method: Through a gambling site
• Exfil: JavaScript with obfuscation. Likely steals user credentials
• Indicators: Domain age 629 days, gambling content, obfuscated Javascript
• Risk: Low

🔒 Obfuscation Detected

  • atob
  • fromCharCode
  • unescape

📡 API Calls Detected

  • HEAD
  • POST

📊 Risk Score Breakdown

Total Risk Score
30/100

Contributing Factors

Javascript Obfuscation
Presence of obfuscated javascript, which may contain malicious code.
Gambling Content
Website provides gambling content, which is often associated with scam websites.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Nemo89 users (International)
Attack Method
obfuscated JavaScript
Exfiltration Channel
Unknown
Risk Assessment
HIGH - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 3 obfuscation techniques

🏢 Brand Impersonation Analysis

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The site likely aims to steal user credentials through forms hidden within Javascript.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
nemo89.net
Registered
None
Registrar
None
Status
None

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.