EN ES PT
Back to Stats

Visual Capture

Screenshot of adladklaskdladklasdkas.onrender.com

Detection Info

https://adladklaskdladklasdkas.onrender.com/
Detected Brand
Banco Pichincha
Country
International
Confidence
95%
HTTP Status
200
Report ID
88d5d309-845…
Analyzed
2026-01-30 08:50

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T17731422150C5197FC003E1ED6380EE62B0C3C506D9427951E3FC895A57E8D41D755DFC
CONTENT ssdeep
24:gY0CxZhVG4TGb4fdW77fYA69D7MXs47cWCNJXqCwE9Hs3wJlrIliHEC:JTde4Y7Zs7MXd7mnqu9HsosgkC

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9b4c66b1ce4c31e6
VISUAL aHash
00000000ffffffff
VISUAL dHash
067155206850594c
VISUAL wHash
00000000ffffffff
VISUAL colorHash
060000001c0
VISUAL cropResistant
680c105810304c0c,9100166930020c71

Code Analysis

Risk Score 80/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester
Discord Webhook

πŸ”¬ Threat Analysis Report

β€’ Threat: Phishing
β€’ Target: Banco Pichincha clients
β€’ Method: Impersonation via a suspicious domain, forms and Javascript.
β€’ Exfil: Discord webhooks
β€’ Indicators: Unrelated domain, form requesting sensitive information, Javascript form submission.
β€’ Risk: HIGH

πŸ“‘ API Calls Detected

  • https://api.ipify.org?format=json

πŸ“Š Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Suspicious Domain
The domain 'adladklaskdladklasdkas.onrender.com' is not related to Banco Pichincha.
Requests Sensitive Information
The form asks for personal and financial information (cedula, email, password).
Javascript Form Submission
JavaScript is used to submit the form, which could be used to exfiltrate data.

πŸ”¬ Comprehensive Threat Analysis

Threat Type
Credential Harvesting Kit
Target
Banco Pichincha users (International)
Attack Method
Brand impersonation + credential harvesting forms
Exfiltration Channel
Discord Webhooks (1 detected)
Risk Assessment
CRITICAL - Automated credential harvesting with Discord Webhooks (1 detected)

⚠️ Indicators of Compromise

  • 1 Discord webhook(s)
  • Kit types: Credential Harvester

🏒 Brand Impersonation Analysis

Impersonated Brand
Banco Pichincha
Fake Service
Credit Card Application

Fraudulent Claims

βš”οΈ Attack Methodology

Primary Method: Credential Harvesting

The attackers are attempting to steal the user's credentials by creating a fake login form that looks like Banco Pichincha's, hosted on a suspicious domain.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
adladklaskdladklasdkas.onrender.com
Registered
None
Registrar
None
Status
Inactive

πŸ”¬ JavaScript Deep Analysis

Total Code Size
192Β bytes

πŸ”— API Endpoints Detected

Discord Webhooks
1

πŸ” Obfuscation Detected

  • : Light

πŸ€– AI-Extracted Threat Intelligence

Scan History for adladklaskdladklasdkas.onrender.com

Found 1 other scan for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.