EN ES PT
Back to Stats

Captura Visual

Screenshot of www.booking-clone-sigma.vercel.app

Información de Detección

http://www.booking-clone-sigma.vercel.app/
Detected Brand
Booking.com
Country
Unknown
Confianza
100%
HTTP Status
200
Report ID
32eacfde-f1f…
Analyzed
2026-01-27 11:26
Final URL (after redirects)
https://booking-clone-sigma.vercel.app/

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1FD831BA43909F5271EB343AB20EE1503B378121B940D4D70B254FD9EB6F9C9AA067FD9
CONTENT ssdeep
1536:/pt4z3j8sLx4TESLwsGSMBDLw1j90+1LmjzQ:sz3jsTTwsiW16+1b

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c26bbd446b9194bc
VISUAL aHash
00007e7c347effff
VISUAL dHash
c2c1d8c8e4e4c006
VISUAL wHash
00003c2c347effff
VISUAL colorHash
030000001c0
VISUAL cropResistant
f0c8c9e4c4c022c0,d0c7c0f8c8e0e4d4,02200113814164a4,b0d0d0e0e0e8f8f0,9eebcd8dadf5f5f4

Análisis de Código

Risk Score 73/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔒 Obfuscation Detected

  • fromCharCode

📊 Desglose de Puntuación de Riesgo

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected Credential Harvester and OTP Stealer kits targeting Booking.com users for account takeover and payment fraud.
Obfuscation Techniques
Three distinct obfuscation techniques detected, indicating attempts to evade detection and analysis.
Brand Impersonation
Domain and site design mimic Booking.com, a high-value target for credential harvesting and financial fraud.
Form-Based Attack
Two forms detected, likely used for credential harvesting and personal information collection.

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Banking Credential Harvester
Objetivo
Booking.com users
Método de Ataque
credential harvesting forms + obfuscated JavaScript
Canal de Exfiltración
Form submission (backend endpoint not detected - likely JavaScript-based)
Evaluación de Riesgo
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 3 obfuscation techniques

🏢 Análisis de Suplantación de Marca

Impersonated Brand
Booking.com
Official Website
https://www.booking.com
Fake Service
Hotel and accommodation booking service

⚔️ Metodología de Ataque

Primary Method: SERVICE - Credential Harvesting

The phishing kit impersonates Booking.com to trick users into entering their login credentials. The harvested credentials are likely exfiltrated in real-time to the attacker's server for immediate account takeover and unauthorized access to booking history and payment methods.

Secondary Method: SERVICE - OTP Interception

The OTP Stealer kit component captures one-time passwords (OTPs) sent via SMS or authenticator apps. This allows attackers to bypass two-factor authentication and gain full access to victim accounts.

🌐 Indicadores de Compromiso de Infraestructura

Domain Information

Dominio
www.booking-clone-sigma.vercel.app
Registered
Unknown
Registrar
Unknown
Estado
Hosting platform (subdomain)

🦠 Malicious Files

Main File
File Size

No specific malicious JavaScript files detected, but obfuscation techniques indicate evasion tactics.

📊 Diagrama de Flujo de Ataque

┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LINK                          │
│    - Email/SMS with fake Booking.com notification         │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM LANDS ON FAKE BOOKING PAGE                     │
│    - Cloned site displays login/booking form             │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT                                      │
│    - User enters Banking/booking credentials             │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA CAPTURE & EXFILTRATION                           │
│    - Form submits credentials via HTTP POST              │
│    - Data sent to attacker-controlled server             │
└──────────────────────────────────────────────────────────┘

🤖 AI-Extracted Threat Intelligence

📊 Attack Flow

┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LINK                          │
│    - Email/SMS with fake Booking.com notification         │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM LANDS ON FAKE BOOKING PAGE                     │
│    - Cloned site displays login/booking form             │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT                                      │
│    - User enters Banking/booking credentials             │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA CAPTURE & EXFILTRATION                           │
│    - Form submits credentials via HTTP POST              │
│    - Data sent to attacker-controlled server             │
└──────────────────────────────────────────────────────────┘

🎯 Malicious Files Identified

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.