EN ES PT
Back to Stats

Visual Capture

Screenshot of entrega-urgente.shop

Detection Info

http://entrega-urgente.shop/
Detected Brand
Will Bank
Country
Brazil
Confidence
100%
HTTP Status
200
Report ID
db661e55-fe7…
Analyzed
2026-03-16 12:05

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T15B32EB7072501ABB91CBD2E1B675AB5BB2C8CB4FCA57D601A3F983844FC3C92DD88214
CONTENT ssdeep
192:qZtrZSf/rKSHnC/MnwtwaocujPJ3O5uxTRWAwzDfS:Mt4jHnCEnwpuj1nJRWAwzDq

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b3333313cccccccc
VISUAL aHash
e7c7e7ffefe7ffff
VISUAL dHash
4d4d4d324c4c322a
VISUAL wHash
e4e4c4ccc8c0fcfc
VISUAL colorHash
07200038000
VISUAL cropResistant
4d4d4d324c4c322a,1f9bab8ff9d9ccde

Code Analysis

Risk Score 76/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Will Bank customers
• Method: Impersonation
• Exfil: Unknown
• Indicators: Domain mismatch, obfuscation, visual similarity
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode
  • unicode_escape

📡 API Calls Detected

  • POST

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain Mismatch
The domain is not related to Will Bank.
Obfuscation
Obfuscated javascript suggests malicious intent.
Impersonation
The site mimics Will Bank's design.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Will Bank users (Brazil)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 6 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Will Bank
Official Website
willbank.com.br
Fake Service
Personal Loans

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The attacker aims to steal user credentials (username and password) by impersonating Will Bank's login page or other forms. The user is tricked into entering their login details on a fake site.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
entregra-urgente.shop
Registered
Unknown
Registrar
Unknown
Status
Unknown

🤖 AI-Extracted Threat Intelligence

Scan History for entrega-urgente.shop

Found 1 other scan for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.