EN ES PT
Back to Stats

Captura Visual

Screenshot of credfacilitadora.netlify.app

Información de Detección

https://credfacilitadora.netlify.app/
Detected Brand
Shopee
Country
Unknown
Confianza
100%
HTTP Status
200
Report ID
b3da307b-121…
Analyzed
2026-01-26 11:12

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T14102A635524E0D3F7103D6A5F2A4777A006AA34FD66F8404F1B90663D6CBECAE827578
CONTENT ssdeep
96:nGHFA1cgx+M73sQ8egsBP146ftUn1o+Mk7EIfyFN4kIwPUNHZkxeJrak88oakXMg:11N6k4ohwv5WTowthzOIz3

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b35d4c73194c6659
VISUAL aHash
00ffffffefe7ffff
VISUAL dHash
144c3014484d3222
VISUAL wHash
0040dbc3c8c0d8d8
VISUAL colorHash
07000038000
VISUAL cropResistant
4c0834524c4d3222,0000343430340800

Análisis de Código

Risk Score 100/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • base64_strings

📡 API Calls Detected

  • GET
  • https://ipapi.co/json/

📊 Desglose de Puntuación de Riesgo

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected Credential Harvester, OTP Stealer, Card Stealer, and Banking kits with real-time interception capabilities.
High Obfuscation
161 obfuscation techniques detected, indicating deliberate evasion of static analysis.
Malicious JavaScript Files
Presence of large (1.1 MB) JavaScript files (fbevents.js, pixel.js, latest.js) with no legitimate purpose identified.
Brand Impersonation
Impersonation of Shopee, a high-value e-commerce target for credential and payment theft.

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Banking Credential Harvester
Objetivo
Shopee users
Método de Ataque
obfuscated JavaScript
Canal de Exfiltración
Unknown
Evaluación de Riesgo
CRITICAL - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 161 obfuscation techniques

🏢 Análisis de Suplantación de Marca

Impersonated Brand
Shopee
Official Website
https://www.shopee.com
Fake Service
Fake Shopee account verification or promotion

⚔️ Metodología de Ataque

Primary Method: Credential Harvesting

The phishing kit captures Shopee user credentials via a fake login portal. Input fields are intercepted in real-time and exfiltrated to attacker-controlled infrastructure.

Secondary Method: OTP and Payment Data Theft

The kit includes modules to steal one-time passwords (OTP) and credit card details, enabling account takeover and unauthorized transactions. Payment data is likely validated client-side before exfiltration.

🌐 Indicadores de Compromiso de Infraestructura

Domain Information

Dominio
credfacilitadora.netlify.app
Registered
Unknown
Registrar
Unknown
Estado
Active (age unknown)

🦠 Malicious Files

Main File
File Size

Large JavaScript file with no legitimate functionality detected, likely used for credential and payment data exfiltration.

📊 Diagrama de Flujo de Ataque

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. INITIAL CONTACT                                       │
│    - Victim receives phishing message (email/SMS)        │
│    - Message contains link to fake Shopee page           │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE PAGE DISPLAY                                     │
│    - Victim visits counterfeit Shopee login page         │
│    - Page mimics legitimate Banking portal               │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL CAPTURE                                    │
│    - Victim enters login credentials                     │
│    - Fake form collects sensitive information            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA TRANSMISSION                                     │
│    - Collected data sent via HTTP POST                   │
│    - Standard form submission to attacker-controlled     │
│      destination                                         │
└──────────────────────────────────────────────────────────┘
```

🔬 JavaScript Deep Analysis

Operator Language
Portuguese (1%)
Sophistication Level
Basic
Total Code Size
1,1 MB

🔗 API Endpoints Detected

Other
44

🔐 Obfuscation Detected

  • : Light
  • : Moderate
  • : Light
  • : Light
  • : Heavy

🤖 AI-Extracted Threat Intelligence

📊 Attack Flow

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. INITIAL CONTACT                                       │
│    - Victim receives phishing message (email/SMS)        │
│    - Message contains link to fake Shopee page           │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE PAGE DISPLAY                                     │
│    - Victim visits counterfeit Shopee login page         │
│    - Page mimics legitimate Banking portal               │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL CAPTURE                                    │
│    - Victim enters login credentials                     │
│    - Fake form collects sensitive information            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA TRANSMISSION                                     │
│    - Collected data sent via HTTP POST                   │
│    - Standard form submission to attacker-controlled     │
│      destination                                         │
└──────────────────────────────────────────────────────────┘
```

🎯 Malicious Files Identified

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.