EN ES PT
Back to Stats

Captura Visual

Screenshot of www.grandprize-jkt058.blogspot.com

Información de Detección

https://www.grandprize-jkt058.blogspot.com/
Detected Brand
Shopee
Country
International
Confianza
100%
HTTP Status
200
Report ID
0e518867-0a8…
Analyzed
2026-01-25 18:06
Final URL (after redirects)
https://grandprize-jkt058.blogspot.com/

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T18573E832D2461103A05B88C8F1269B4D73528749CA138FB976FD17B9EACECB5676239C
CONTENT ssdeep
1536:UYDJZn7huO5fsyXHdVQRwadqYWWxOLsRqwQVSiVkgynKnnnjeeeeeaUnnepeeec0:LUO5H0KLmQsiT5xk222I2222222Ds3PF

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c02ecd329993ef4c
VISUAL aHash
fb00707e4c407c7f
VISUAL dHash
8aaee6d8888ad8ba
VISUAL wHash
7340727e42427e7e
VISUAL colorHash
06600030000
VISUAL cropResistant
8aaee6d8888ad8ba,8692939325651f23,8692939325651f23,499964f1330f2b22,8692939325651f23,8692939325651f23,4b4b7198d8d08c4d,3692db4bd21a2b2b,2565477747496b21,8692939325651f23,8692939325651f23

Análisis de Código

Risk Score 79/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Amenaza: Sitio web de phishing que suplanta a Shopee.
• Objetivo: Usuarios de Shopee, particularmente en Indonesia o el sudeste asiático.
• Método: Muestra una página de destino falsa con contenido promocional y enlaces potencialmente maliciosos.
• Exfil: Probablemente redirige a otros sitios de phishing o intenta instalar malware.
• Indicadores: Alojamiento gratuito en blogspot.com, JavaScript ofuscado y un dominio no relacionado con el sitio oficial de Shopee.
• Riesgo: ALTO - Potencial de infección por malware y robo de credenciales.

🔒 Obfuscation Detected

  • eval
  • hex_escape
  • unicode_escape

🎯 Kit Endpoints

  • https://www.blogger.com/profile/02537498262821970087
  • https://www.blogger.com/feeds/4847980147523367173/posts/default
  • https://grandprize-jkt058.blogspot.com/feeds/posts/default?alt=rss
  • https://www.blogger.com
  • https://grandprize-jkt058.blogspot.com/feeds/posts/default
  • https://api.whatsapp.com/send?phone=6281524184058&text=Silahkan%20Konfirmasikan%20%0ANama%20Lengkap%20%3A%0APIN%20Pemenang%20%3A%0ANomor%20HP%20%3A
  • https://grandprize-jkt058.blogspot.com/
  • https://www.blogger.com/dyn-css/authorization.css?targetBlogID=4847980147523367173&zx=9cb1f56c-be3f-4cc3-87d1-52b6161b1baf

📡 API Calls Detected

  • post

📊 Desglose de Puntuación de Riesgo

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected Credential Harvester, OTP Stealer, and Banking kits targeting Shopee users.
High Obfuscation
36 obfuscation techniques detected in JavaScript files, indicating evasion of detection.
Brand Impersonation
Impersonates Shopee, a high-value e-commerce brand, to deceive victims.
Reward-Based Social Engineering
Uses 'grand prize' reward tactic to lure victims into interacting with the phishing page.

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Brand Impersonation (Shopee)
Objetivo
Shopee users (International)
Canal de Exfiltración
N/A (Landing page - no direct data collection)

🏢 Análisis de Suplantación de Marca

Impersonated Brand
Shopee
Official Website
https://www.shopee.com
Fake Service
Grand prize giveaway

Fraudulent Claims

⚔️ Metodología de Ataque

Primary Method: Credential Harvesting

The phishing kit captures user credentials (username, password) via fake login forms mimicking Shopee's authentication flow. Data is likely exfiltrated to an attacker-controlled server in real-time.

Secondary Method: OTP Stealer

The kit includes functionality to intercept one-time passwords (OTPs) sent via SMS or email, enabling attackers to bypass two-factor authentication (2FA) protections.

🌐 Indicadores de Compromiso de Infraestructura

Domain Information

Dominio
www.grandprize-jkt058.blogspot.com
Registered
Unknown
Registrar
None
Estado
Active (age unknown)

🦠 Malicious Files

Main File
File Size

JavaScript file containing obfuscated code for credential harvesting and OTP interception.

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
144,4 KB

🔗 API Endpoints Detected

Other
8

🔐 Obfuscation Detected

  • : Heavy

🤖 AI-Extracted Threat Intelligence

🎯 Malicious Files Identified

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.