EN ES PT
Back to Stats

Visual Capture

Screenshot of nacarinvestorio.net

Detection Info

https://nacarinvestorio.net/
Detected Brand
Nácar Investorio (Investment/Finance Fraud)
Country
International
Confidence
100%
HTTP Status
200
Report ID
fb89e8bd-208…
Analyzed
2026-08-12 23:20

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1F632A57550847D37869392C8F772E31FF2C286C496A78761F2FC8B1E5AC4EA6CC19119
CONTENT ssdeep
192:shApUHOizof4mU+yL10loAc1Adu0AoWt5:GAnizof4mUjLmNdu9oA5

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
8b29b569da4bcad0
VISUAL aHash
ff011901000000ff
VISUAL dHash
ebebe3e3e3e3cbcd
VISUAL wHash
ff031911313129ff
VISUAL colorHash
07e00000000
VISUAL cropResistant
2bebebcbebf3f3eb,1a128e4e464d4b8a,cdcbcbcb00800000,cbfbe3ebe3e3cbcb

Code Analysis

Risk Score 76/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Financial Investment Phishing
• Target: Financial credentials/Investor funds
• Method: Deceptive landing page with JS-based data exfiltration
• Exfil: JavaScript form hijacking
• Indicators: Newly registered domain, code obfuscation
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode
  • unescape

📡 API Calls Detected

  • POST
  • /api/sms/send
  • /api/sms-verification-status
  • /api/sms/verify

📊 Risk Score Breakdown

Total Risk Score
95/100

Contributing Factors

Recent Domain
Domain is 0 days old
Malicious Code
Detected obfuscated JS exfiltration

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Nácar Investorio (Investment/Finance Fraud) users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 3 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Nácar Investorio
Fake Service
Investment Platform

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting / Investment Fraud

The site uses a landing page to lure users into providing contact details or funds, then utilizes obfuscated scripts to transmit that data to an attacker-controlled server.

Secondary Method: Social Engineering

Uses professional financial aesthetics to build false trust.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
nacarinvestorio.net
Registered
2026-08-12
Registrar
Unknown
Status
Newly Registered

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.