EN ES PT
Back to Stats

Visual Capture

Screenshot of rebrand.ly

Detection Info

https://rebrand.ly/ux86de6
Detected Brand
PayPal
Country
International
Confidence
100%
HTTP Status
200
Report ID
faa0d1dd-d58โ€ฆ
Analyzed
2026-02-10 00:37
Final URL (after redirects)
https://www.paypal.com/us/home

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1FD44C2785918AC2E0641848DE1CF3798B15FC24A8B0247ABB36B2D7F87E14B7757C663
CONTENT ssdeep
1536:r3OOtc2B1U1g14yHJ4BHp2c3or502X2y2/HiHplFXWXHiuH31VxUgoC1wIUF:r3BOAGVup8c

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
f08ad28b74a9de70
VISUAL aHash
ffe7c3c3c3ffc2c0
VISUAL dHash
59482a9696695c54
VISUAL wHash
ff204343c3ffc0c0
VISUAL colorHash
01007000000
VISUAL cropResistant
59482a9696695c54,69e48d6b8b8ad232,0555a9a93763b9ac,44946c69b2967175,12326226995bc9c9,d9999ae56515d5d5,3979f8a8ade9a3b1,33ccac4cce9c8c63

Code Analysis

Risk Score 85/100
Threat Level ALTO
โš ๏ธ Phishing Confirmed
๐ŸŽฃ Credential Harvester ๐ŸŽฃ OTP Stealer ๐ŸŽฃ Card Stealer ๐ŸŽฃ Banking ๐ŸŽฃ Personal Info

๐Ÿ”ฌ Threat Analysis Report

โ€ข Threat: Phishing
โ€ข Target: PayPal users
โ€ข Method: URL redirection and social engineering
โ€ข Exfil: JavaScript obfuscation may indicate data exfiltration. The final URL after the redirect is unknown, so the location is also unknown.
โ€ข Indicators: URL shortener, impersonation, javascript obfuscation, javascript form submission.
โ€ข Risk: HIGH

๐Ÿ”’ Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • document.write
  • unicode_escape
  • js_packer
  • base64_strings

๐ŸŽฏ Kit Endpoints

  • /us/digital-wallet/send-receive-money/send-money?locale.x=en_US
  • https://www.paypal.com/us/digital-wallet/send-receive-money/pool-money
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/PricingCardTableRebrand-e59d1e27.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/NavBanner-0e476819.js
  • https://www.msmaster.qa.paypal.com/contentmanager
  • https://www.paypalobjects.com/pa/3pjs/tl/6.4.157/patlcfg.js
  • https://www.paypalobjects.com/pa/3pjs/glassbox/detector-dom.min.js
  • https://adobe.ly/3sHgQHb
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/ScrollStickyButton-96dc9211.js
  • https://www.paypalobjects.com/globalnav/js/main-BptD1Wyh.js
  • https://www.youtube-nocookie.com/embed/${e}?autoplay=1&rel=0&autohide=2&border=0&wmode=opaque&showinfo=0&hd=1&playsinline=1&enablejsapi=1`,Ib=new
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/TabControllerGridItem-852a7038.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/OfferCardType-b73c43dd.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/TextHeaderInner-f693b97a-e1cf33fc.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/SplitGraphicSectionType-d7cd9e7a.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/SubNav-a0064f0b.js
  • /us/digital-wallet/send-receive-money?locale.x=en_US
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/index-8ae288e1-584fb91f.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/AppDownloadGroup-811742a7.js
  • /us/digital-wallet/send-receive-money/request-money?locale.x=en_US
  • https://www.datadoghq-browser-agent.com
  • https://www.paypalobjects.com/helpcenter/smartchat/sales/v1/open-chat.js
  • https://ddbm2.paypal.com/js/
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/PpReactCurrencyInput-35f9b855-92d02e2b.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/TabControllerGridItem-7ffc6555-e845d5af.js
  • https://www.paypal.com/us/digital-wallet/send-receive-money/send-money
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/Spacer-6ff81921.js
  • /us/digital-wallet/send-receive-money/pool-money?locale.x=en_US
  • https://www.paypalobjects.com/pa/3pjs/tl/6.4.65/patleaf.js
  • http://a
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/useStickyElementHeight-0dbaade3-a1416799.js
  • https://ns.adobe.com/personalization/redirect-item
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/FeatureColumnType-033e0a90.js
  • /us/digital-wallet/send-receive-money/start-selling?locale.x=en_US
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/CurrencyListSection-0eebced6.js
  • http://test/path
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/BrandSplashSection-6310d414.js
  • /us/digital-wallet/send-receive-money/giving?locale.x=en_US
  • https://www.paypal.com/us/digital-wallet/send-receive-money/request-money

๐Ÿ“ก API Calls Detected

  • POST
  • post
  • GET
  • get

๐Ÿ“Š Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Active Phishing Kit
URL Shortener combined with impersonation of a well-known brand and Javascript obfuscation indicate the presence of an active phishing campaign.
Impersonation
The page mimics the design of a legitimate PayPal page, increasing the chances of users falling victim to the phishing scam.
Suspicious Code
Javascript obfuscation and the presence of javascript form submissions.

๐Ÿ”ฌ Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
PayPal users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

โš ๏ธ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 730 obfuscation techniques

๐Ÿข Brand Impersonation Analysis

Impersonated Brand
PayPal
Official Website
paypal.com
Fake Service
PayPal website

โš”๏ธ Attack Methodology

Primary Method: Credential Harvesting

The attacker aims to steal user credentials by redirecting them to a fake login page that mimics PayPal's legitimate site. Javascript obfuscation and form submission detection suggest the use of javascript to harvest and send the user's data to a malicious server.

Secondary Method: Redirection

The use of rebrand.ly is a method of hiding the malicious destination. The redirect is a form of social engineering.

๐ŸŒ Infrastructure Indicators of Compromise

๐Ÿฆ  Malicious Files

Main File
mktconf.js
File Size

๐Ÿ”ฌ JavaScript Deep Analysis

Operator Language
English (1%)
Sophistication Level
Basic
Total Code Size
1.8ย MB

๐Ÿ”— API Endpoints Detected

Other
175

๐Ÿ” Obfuscation Detected

  • : Moderate
  • : Light
  • : Moderate
  • : Heavy
  • : Light
  • : None
  • : Light
  • : None
  • : None
  • : Light
  • : None
  • : Light

๐Ÿค– AI-Extracted Threat Intelligence

๐ŸŽฏ Malicious Files Identified

Main Drainer
mktconf.js
File Size
1843KB

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

๐Ÿ˜ฐ
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.