EN ES PT
Back to Stats

Captura Visual

Screenshot of zxcursed0mifony-hash.github.io

Información de Detección

https://zxcursed0mifony-hash.github.io/Vkontakte
Detected Brand
VKontakte
Country
Unknown
Confianza
100%
HTTP Status
200
Report ID
e70213b9-195…
Analyzed
2026-08-31 10:25
Final URL (after redirects)
https://zxcursed0mifony-hash.github.io/Vkontakte/

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T16672146633229B2DB053F4B87771A6327D8D80A5A95763B4C7B35E34F0AFC509DA0E84
CONTENT ssdeep
384:rfsa46Jsa4FXlsa46Jsa4Ffmsa4tlsa4Pz:LeyeZleyeVmeHeb

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
bd16c2a956dd3912
VISUAL aHash
ffff81800199ffff
VISUAL dHash
108a333333331288
VISUAL wHash
ffbf00800081bdff
VISUAL colorHash
07007000000
VISUAL cropResistant
108a333333331288

Análisis de Código

Risk Score 25/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
Telegram Exfiltration

🔑 Telegram Bot Tokens (1)

  • 8712563091:AAEg...gZWBn6gg

📊 Desglose de Puntuación de Riesgo

Total Risk Score
70/100

Contributing Factors

Credential Harvesting
Credential harvesting detected with 6 form(s) capturing sensitive data
Telegram Exfiltration
Real-time data exfiltration via Telegram (1 bot token(s) exposed in client-side code)

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Data Exfiltration Campaign
Objetivo
VKontakte users
Método de Ataque
credential harvesting forms
Canal de Exfiltración
Telegram Bot (8712563091:AAEg-wCQ4...)
Evaluación de Riesgo
LOW - Automated credential harvesting with Telegram Bot (8712563091:AAEg-wCQ4...)

⚠️ Indicators of Compromise

  • 1 Telegram bot token(s)

🏢 Análisis de Suplantación de Marca

Impersonated Brand
VKontakte
Official Website
N/A
Fake Service
Credential harvesting service

⚔️ Metodología de Ataque

Primary Method: VKontakte Credential Harvesting

Fake VKontakte login page with 6 forms. Victim enters credentials which are captured and transmitted to attacker's server. Page may impersonate VKontakte official login to appear legitimate.

Secondary Method: Client-Side Form Interception

JavaScript intercepts form submissions before they reach the fake backend. This allows real-time credential harvesting and validation without server round-trips.

📡 Infraestructura de Comando y Control Telegram

Bot Token (Masked)
8712563091:AAEg...gZWBn6gg
Bot ID
8712563091
Group/Chat ID
Unknown
Operator Language
Unknown

💬 Message Templates (3)

ID Portugués Inglés Trigger

🌐 Indicadores de Compromiso de Infraestructura

Domain Information

Dominio
zxcursed0mifony-hash.github.io
Registered
Unknown
Registrar
Unknown
Estado
Hosting platform (subdomain)

Hosting Information

Provider
Unknown
ASN

🤖 AI-Extracted Threat Intelligence

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.