EN ES PT
Back to Stats

Captura Visual

No screenshot available

Información de Detección

https://store.workshopviewreward.com/sharedfiles/filedetails?id=3364147275
Detected Brand
Steam
Country
International
Confianza
100%
HTTP Status
200
Report ID
d858e30d-1e8…
Analyzed
2026-01-25 23:49

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T14343D7F0A165A67B019BB2D3B739AB1E26D2870AD64747E0D2FC836C1BD5D50DD3B028
CONTENT ssdeep
1536:dxvGd6C8BH1lnfK0Th+OG9GC3X3Y0eGC+pma6M:bvGdA3DaSM

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
cb6564129cc76799
VISUAL aHash
00203c3c3c3c3c38
VISUAL dHash
4948506171696960
VISUAL wHash
243c3c3c3c3c3e3e
VISUAL colorHash
08007000000
VISUAL cropResistant
37367afaf0c2e3e3,4948506171696960

Análisis de Código

Risk Score 97/100
Nivel de Amenaza BAJO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Amenaza: Potencial distribución de contenido malicioso en el Workshop.
• Objetivo: Usuarios de Steam interesados en Team Fortress 2.
• Método: Distribución de un activo de juego modificado a través del Steam Workshop.
• Exfil: N/A
• Indicators: Contenido de Workshop disponible en Steam.
• Risk: BAJO - Riesgo potencial de malware si el artículo del Workshop es malicioso.

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • document.write
  • unicode_escape
  • js_packer
  • base64_strings

📡 API Calls Detected

  • get
  • POST

📤 Form Action Targets

  • https://steamcommunity.com/workshop/updatekvtags/

📊 Desglose de Puntuación de Riesgo

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected Credential Harvester, OTP Stealer, Card Stealer, and Banking kits with real-time form interception (15 forms identified).
Brand Impersonation
Impersonates Steam, a high-value target for credential harvesting and financial fraud.
Obfuscation Techniques
40200 obfuscation techniques detected, indicating advanced evasion of static analysis.
Malicious JavaScript
Large JavaScript files (2.91 MB total) with no legitimate purpose identified.

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Banking Credential Harvester
Objetivo
Steam users (International)
Método de Ataque
credential harvesting forms + obfuscated JavaScript
Canal de Exfiltración
HTTP POST to backend
Evaluación de Riesgo
CRITICAL - Automated credential harvesting with HTTP POST to backend

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 40200 obfuscation techniques

🏢 Análisis de Suplantación de Marca

Impersonated Brand
Steam
Official Website
https://store.steampowered.com
Fake Service
Fake reward or file-sharing service (e.g., 'Workshop View Reward')

⚔️ Metodología de Ataque

Primary Method: Credential Harvesting

The phishing kit captures Steam account credentials via fake login forms. Input fields are intercepted in real-time and exfiltrated to attacker-controlled servers, enabling immediate account takeover.

Secondary Method: OTP and Payment Data Theft

Secondary forms target one-time passwords (OTP) and payment card details, likely using fake authentication prompts or transaction verification pages to trick victims into submitting sensitive data.

🌐 Indicadores de Compromiso de Infraestructura

Domain Information

Dominio
store.workshopviewreward.com
Registered
2026-01-16 16:40:46+00:00
Registrar
Global Domain Group LLC
Estado
Recently registered (9 days old)

🦠 Malicious Files

Main File
File Size

Large JavaScript file with advanced obfuscation, likely used for credential and payment data interception.

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
2,9 MB

🔗 API Endpoints Detected

Other
90
WebSocket (Real-time)
1

🔐 Obfuscation Detected

  • : None
  • : None
  • : None
  • : None
  • : Light
  • : Light
  • : Moderate
  • : None
  • : Light
  • : Light
  • : None
  • : Light
  • : None
  • : None
  • : Light
  • : None
  • : Light
  • : Light
  • : Heavy
  • : Moderate

🤖 AI-Extracted Threat Intelligence

🎯 Malicious Files Identified

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.