EN ES PT
Back to Stats

Captura Visual

Screenshot of avertron.net

Información de Detección

http://avertron.net
Detected Brand
Avertron AI
Country
Belgium
Confianza
95%
HTTP Status
200
Report ID
f82abab8-7b2…
Analyzed
2026-01-26 13:42
Final URL (after redirects)
https://avertron.net/

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1E0D2723460C5A9270887B2D1F7761B5BB7A09340D253870992FCCB5E2FD3C98DD2A5B4
CONTENT ssdeep
384:HjkTddTPsutWl+N8E1Pqu3IgKMmw084N59Iy55ym/sRANb8wYTFo3iWJg:H/ur1PJ3IgKhR8m59v/VNbnYGc

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
da34e9e9345a9469
VISUAL aHash
0000060606fff9ff
VISUAL dHash
92cc9cac9c233b23
VISUAL wHash
000006060fffffff
VISUAL colorHash
1b002000180
VISUAL cropResistant
a080a07060c080a0,a28098da5a9080aa,808088fa3ab880b2,9200b8badaf80042,0411ea9292ca1582,9b00332b3b330323,921ecc8c9cacac98,317978b93c3c7a7e

Análisis de Código

Risk Score 66/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer

🔬 Threat Analysis Report

• Amenaza: Estafa de phishing de inversión en criptomonedas
• Objetivo: Ciudadanos belgas interesados en el comercio de criptomonedas
• Método: Un sitio web engañoso promete ganancias diarias garantizadas a través del comercio automatizado de IA, recopilando información personal a través de un formulario de registro.
• Exfil: Datos enviados a validation/thankyou.php (potencialmente API personalizada)
• Indicadores: Dominio nuevo, reclamos de ganancias poco realistas, exfiltración de datos de formularios y tácticas de urgencia.
• Riesgo: ALTO - Posible pérdida financiera y robo de identidad.

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • document.write
  • unicode_escape

📡 API Calls Detected

  • https://ipapi.co/json
  • https://ipapi.co/json/
  • /validation/style.php
  • POST

📤 Form Action Targets

  • validation/thankyou.php

📊 Desglose de Puntuación de Riesgo

Total Risk Score
90/100

Contributing Factors

Active Phishing Kit
Detected OTP Stealer kit with form interception capabilities targeting personal information and potential OTP theft.
High Obfuscation
32 obfuscation techniques detected in JavaScript files, indicating deliberate evasion of detection.
Urgency and Reward Tactics
Uses high-reward claims (€975 daily benefit) and urgency (only 38 spots remaining) to manipulate victims.
Suspicious Domain
Domain avertron.net is not associated with the official Avertron AI brand and lacks legitimate infrastructure (no IPs or nameservers detected).
Form-Based Credential Harvesting
Single form detected with fields for first name, last name, and email, likely used for credential harvesting.

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Two-Factor Authentication Stealer
Objetivo
Avertron AI users (Belgium)
Método de Ataque
credential harvesting forms + obfuscated JavaScript
Canal de Exfiltración
HTTP POST to backend
Evaluación de Riesgo
HIGH - Automated credential harvesting with HTTP POST to backend

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer
  • 32 obfuscation techniques

🏢 Análisis de Suplantación de Marca

Impersonated Brand
Avertron AI
Official Website
https://www.avertron.ai
Fake Service
Exclusive daily financial benefit for Belgian citizens

Fraudulent Claims

⚔️ Metodología de Ataque

Primary Method: Credential Harvesting with OTP Interception

The phishing kit is designed to harvest personal information (first name, last name, email) via a web form. Given the kit type (OTP Stealer), it likely intercepts one-time passwords (OTPs) sent to victims via SMS or email, enabling attackers to bypass 2FA protections on compromised accounts.

Secondary Method: Social Engineering (Reward and Urgency Tactics)

The campaign employs psychological manipulation by promising a daily benefit of €975 and creating urgency with a limited number of spots (38 remaining). This tactic pressures victims into submitting their personal information without critical evaluation.

🌐 Indicadores de Compromiso de Infraestructura

Domain Information

Dominio
avertron.net
Registered
2026-01-26 09:40:29+00:00
Registrar
PDR Ltd. d/b/a PublicDomainRegistry.com
Estado
Recently registered (0 days old)

🦠 Malicious Files

Main File
File Size

Contains obfuscated code likely used for form interception and credential harvesting.

📊 Diagrama de Flujo de Ataque

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. INITIAL COMPROMISE                                    │
│    - Victim receives phishing link                       │
│    - Redirects to fake Avertron AI Banking page          │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. CREDENTIAL COLLECTION                                 │
│    - Victim enters login credentials                     │
│    - Fake page captures input                            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. OTP INTERCEPTION                                      │
│    - Fake page requests one-time password                │
│    - Victim enters OTP code                              │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION                                     │
│    - Collected credentials sent via HTTP POST            │
│    - Standard form submission to attacker server         │
└──────────────────────────────────────────────────────────┘
```

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
58,4 KB

🔗 API Endpoints Detected

Other
5

🔐 Obfuscation Detected

  • : None
  • : None
  • : None
  • : Light

🤖 AI-Extracted Threat Intelligence

📊 Attack Flow

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. INITIAL COMPROMISE                                    │
│    - Victim receives phishing link                       │
│    - Redirects to fake Avertron AI Banking page          │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. CREDENTIAL COLLECTION                                 │
│    - Victim enters login credentials                     │
│    - Fake page captures input                            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. OTP INTERCEPTION                                      │
│    - Fake page requests one-time password                │
│    - Victim enters OTP code                              │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION                                     │
│    - Collected credentials sent via HTTP POST            │
│    - Standard form submission to attacker server         │
└──────────────────────────────────────────────────────────┘
```

🎯 Malicious Files Identified

Scan History for avertron.net

Found 1 other scan for this domain

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.