EN ES PT
Back to Stats

Captura Visual

Screenshot of rebrand.ly

Información de Detección

https://rebrand.ly/ux86de6
Detected Brand
PayPal
Country
International
Confianza
100%
HTTP Status
200
Report ID
faa0d1dd-d58…
Analyzed
2026-02-10 00:37
Final URL (after redirects)
https://www.paypal.com/us/home

Hashes de Contenido (Similitud HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1FD44C2785918AC2E0641848DE1CF3798B15FC24A8B0247ABB36B2D7F87E14B7757C663
CONTENT ssdeep
1536:r3OOtc2B1U1g14yHJ4BHp2c3or502X2y2/HiHplFXWXHiuH31VxUgoC1wIUF:r3BOAGVup8c

Hashes Visuales (Similitud de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
f08ad28b74a9de70
VISUAL aHash
ffe7c3c3c3ffc2c0
VISUAL dHash
59482a9696695c54
VISUAL wHash
ff204343c3ffc0c0
VISUAL colorHash
01007000000
VISUAL cropResistant
59482a9696695c54,69e48d6b8b8ad232,0555a9a93763b9ac,44946c69b2967175,12326226995bc9c9,d9999ae56515d5d5,3979f8a8ade9a3b1,33ccac4cce9c8c63

Análisis de Código

Risk Score 85/100
Nivel de Amenaza ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Amenaza: Phishing
• Objetivo: Usuarios de PayPal
• Método: Redirección de URL e ingeniería social
• Exfil: La ofuscación de JavaScript puede indicar exfiltración de datos. La URL final después de la redirección es desconocida, por lo que la ubicación también es desconocida.
• Indicadores: Acortador de URL, suplantación, ofuscación de javascript, envío de formularios javascript.
• Riesgo: ALTO

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • document.write
  • unicode_escape
  • js_packer
  • base64_strings

🎯 Kit Endpoints

  • /us/digital-wallet/send-receive-money/send-money?locale.x=en_US
  • https://www.paypal.com/us/digital-wallet/send-receive-money/pool-money
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/PricingCardTableRebrand-e59d1e27.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/NavBanner-0e476819.js
  • https://www.msmaster.qa.paypal.com/contentmanager
  • https://www.paypalobjects.com/pa/3pjs/tl/6.4.157/patlcfg.js
  • https://www.paypalobjects.com/pa/3pjs/glassbox/detector-dom.min.js
  • https://adobe.ly/3sHgQHb
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/ScrollStickyButton-96dc9211.js
  • https://www.paypalobjects.com/globalnav/js/main-BptD1Wyh.js
  • https://www.youtube-nocookie.com/embed/${e}?autoplay=1&rel=0&autohide=2&border=0&wmode=opaque&showinfo=0&hd=1&playsinline=1&enablejsapi=1`,Ib=new
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/TabControllerGridItem-852a7038.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/OfferCardType-b73c43dd.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/TextHeaderInner-f693b97a-e1cf33fc.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/SplitGraphicSectionType-d7cd9e7a.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/SubNav-a0064f0b.js
  • /us/digital-wallet/send-receive-money?locale.x=en_US
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/index-8ae288e1-584fb91f.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/AppDownloadGroup-811742a7.js
  • /us/digital-wallet/send-receive-money/request-money?locale.x=en_US
  • https://www.datadoghq-browser-agent.com
  • https://www.paypalobjects.com/helpcenter/smartchat/sales/v1/open-chat.js
  • https://ddbm2.paypal.com/js/
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/PpReactCurrencyInput-35f9b855-92d02e2b.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/TabControllerGridItem-7ffc6555-e845d5af.js
  • https://www.paypal.com/us/digital-wallet/send-receive-money/send-money
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/Spacer-6ff81921.js
  • /us/digital-wallet/send-receive-money/pool-money?locale.x=en_US
  • https://www.paypalobjects.com/pa/3pjs/tl/6.4.65/patleaf.js
  • http://a
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/useStickyElementHeight-0dbaade3-a1416799.js
  • https://ns.adobe.com/personalization/redirect-item
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/FeatureColumnType-033e0a90.js
  • /us/digital-wallet/send-receive-money/start-selling?locale.x=en_US
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/CurrencyListSection-0eebced6.js
  • http://test/path
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/BrandSplashSection-6310d414.js
  • /us/digital-wallet/send-receive-money/giving?locale.x=en_US
  • https://www.paypal.com/us/digital-wallet/send-receive-money/request-money

📡 API Calls Detected

  • POST
  • post
  • GET
  • get

📊 Desglose de Puntuación de Riesgo

Total Risk Score
90/100

Contributing Factors

Active Phishing Kit
URL Shortener combined with impersonation of a well-known brand and Javascript obfuscation indicate the presence of an active phishing campaign.
Impersonation
The page mimics the design of a legitimate PayPal page, increasing the chances of users falling victim to the phishing scam.
Suspicious Code
Javascript obfuscation and the presence of javascript form submissions.

🔬 Análisis Integral de Amenazas

Tipo de Amenaza
Banking Credential Harvester
Objetivo
PayPal users (International)
Método de Ataque
Brand impersonation + obfuscated JavaScript
Canal de Exfiltración
Form submission (backend endpoint not detected - likely JavaScript-based)
Evaluación de Riesgo
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 730 obfuscation techniques

🏢 Análisis de Suplantación de Marca

Impersonated Brand
PayPal
Official Website
paypal.com
Fake Service
PayPal website

⚔️ Metodología de Ataque

Primary Method: Credential Harvesting

The attacker aims to steal user credentials by redirecting them to a fake login page that mimics PayPal's legitimate site. Javascript obfuscation and form submission detection suggest the use of javascript to harvest and send the user's data to a malicious server.

Secondary Method: Redirection

The use of rebrand.ly is a method of hiding the malicious destination. The redirect is a form of social engineering.

🌐 Indicadores de Compromiso de Infraestructura

🦠 Malicious Files

Main File
mktconf.js
File Size

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Sophistication Level
Basic
Total Code Size
1,8 MB

🔗 API Endpoints Detected

Other
175

🔐 Obfuscation Detected

  • : Moderate
  • : Light
  • : Moderate
  • : Heavy
  • : Light
  • : None
  • : Light
  • : None
  • : None
  • : Light
  • : None
  • : Light

🤖 AI-Extracted Threat Intelligence

🎯 Malicious Files Identified

Main Drainer
mktconf.js
File Size
1843KB

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"Nunca pensé que me pasaría a mí"
Esto dicen las 2.3 millones de víctimas cada año. No esperes a ser una estadística.