EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

https://stealsabrainrot.com/
Detected Brand
Unknown
Country
International
Confidence
85%
HTTP Status
200
Report ID
971cc605-1ac…
Analyzed
2026-06-14 04:10

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T14D1247B1D6999C7732A391D89775AB4B38CAC709CE471A0652FCC34D0BD6C45CCBA3A8
CONTENT ssdeep
96:Tmu5/SFA8e/9X7oXqX76XAXGXRXK/XoSXZXOdX+9XuawXFgXbedXvJdXJXgIX7X2:7KO8whZSkIieRJOMGaQSO

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
bf07826d1ac5f8c8
VISUAL aHash
0020bf0001cbffdf
VISUAL dHash
4c4d484d332b0e2d
VISUAL wHash
0000bf2703a3ffdf
VISUAL colorHash
06007000000
VISUAL cropResistant
4c4d484d332b0e2d

Code Analysis

Risk Score 62/100
Threat Level MEDIO
⚠️ Phishing Confirmed
🎣 OTP Stealer

🔬 Threat Analysis Report

• Threat: Phishing/Account Harvesting
• Target: Users (Roblox/Social Media implied)
• Method: Generator lure
• Exfil: JavaScript obfuscation
• Indicators: Obfuscated code, suspicious notification pop-ups
• Risk: Moderate

🔒 Obfuscation Detected

  • atob
  • fromCharCode
  • unescape
  • base64_strings

📡 API Calls Detected

  • POST

📊 Risk Score Breakdown

Total Risk Score
65/100

Contributing Factors

JavaScript Obfuscation
Use of atob/fromCharCode to hide source behavior.
Deceptive Content
Generator-style social engineering targeting users.

🔬 Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
General public
Attack Method
obfuscated JavaScript
Exfiltration Channel
Unknown
Risk Assessment
HIGH - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer
  • 10 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
N/A
Fake Service
Brainrot Generator

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

Prompts users for usernames to engage them in a fake reward process.

Secondary Method: Social Engineering

Uses fake notification popups to trick the user into thinking others are successfully using the site.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
stealsabrainrot.com
Registered
2025-09-18
Registrar
None
Status
None

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.