EN ES PT
Back to Stats

Captura Visual

Screenshot of s.teams-lc.com

Informações de Detecção

https://s.teams-lc.com/p/fjbd-cbch/xsywcbsv/
Detected Brand
Steam
Country
International
Confiança
100%
HTTP Status
200
Report ID
19da5aba-2b1…
Analyzed
2026-02-14 23:48

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1452365F390A4D077078EF6E0B566671FB7C3878BD9460FE29AE847185E86DC18E1341A
CONTENT ssdeep
768:I1gMkvdq3FGMq6COFXQdC3gf6IgMkvdq3FGMq6COd2/RPdXsiK08c2705C81O7pN:I1gMkvdq3FGMq6COFXQdC3gfNgMkvdqt

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
853e6f634f1411dc
VISUAL aHash
00005e7e7e6e7e7e
VISUAL dHash
41ecb4b2d2cac6f2
VISUAL wHash
00005e5e7e6e7e7a
VISUAL colorHash
0e007000000
VISUAL cropResistant
3222b2b2dacad2d2,41ecb4b2d2cac6f2,4153666749491939,89c9390f23636663

Análise de Código

Risk Score 85/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Ameaça: Phishing
• Alvo: Usuários do Steam
• Método: Impersonificação com formulários maliciosos
• Exfil: Potencialmente credenciais do usuário
• Indicadores: Domínio suspeito, Javascript ofuscado, envio de formulário.
• Risco: ALTO

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • document.write
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • http://jedwatson.github.io/classnames
  • https://community.akamai.steamstatic.com/public/images/
  • https://steamcommunity.com/chat/friend/
  • https://player.vimeo.com/video/
  • https://community.akamai.steamstatic.com/public/images/promo/summer2017/stickers_group.png
  • https://store.steampowered.com//account/preferences/#CommunityContentPreferences
  • https://community.akamai.steamstatic.com/public/shared/javascript/shared_global.js?v=yJGtNz8wf36p&l=english&_cdn=akamai
  • https://steamcommunity.com/moderation/ajaxupdateprofiletextcontentcheckresult/
  • https://steamcommunity.com/sharedfiles/share/?id=
  • https://steamcommunity.com/news/shareonsteam/
  • https://steamcommunity.com
  • https://steamcommunity.com/sharedfiles/shareonsteam/?id=
  • https://steamcommunity.com/sharedfiles/banupvoters
  • https://steamcommunity.com/actions/RemoveFriendAjax
  • https://community.akamai.steamstatic.com/public/images/promo/summer2017/stickers/
  • https://react.dev/errors/
  • https://community.akamai.steamstatic.com/public/javascript/applications/community/main.js?v=j292_axB47tc&l=english&_cdn=akamai
  • https://store.steampowered.com/
  • https://steamcommunity.com/news/sharepost/
  • https://steamcommunity.com/sharedfiles/getreports/?id=
  • http://sizzlejs.com/
  • https://steamcommunity.com/sharedfiles/resetreportedcount
  • http://script.aculo.us,
  • https://community.akamai.steamstatic.com/public/shared/images/header/logo_steam.svg?t=962016
  • http://www.apache.org/licenses/LICENSE-2.0
  • https://steamloopback.host
  • https://steamcommunity.com/tradeoffer/
  • https://steamcommunity.com/chat/group/
  • https://steamcommunity.com/trademark/createtrademarkcomplaint/
  • https://steamcommunity.com/login/home/?goto=profiles%2F76561199219712055%2F%3Fl%3Denglish
  • https://steamcommunity.com/actions/ReportProfile/
  • https://community.akamai.steamstatic.com/public/images/skin_1/footerLogo_valve.png?v=1
  • https://steamcommunity.com/userreviews/clearcontentcheckresults/

📡 API Calls Detected

  • get
  • POST

📊 Detalhamento da Pontuação de Risco

Total Risk Score
90/100

Contributing Factors

Recent Domain
Domain age of 4 days is highly suspicious.
Obfuscated Javascript
Javascript obfuscation is frequently used to hide malicious behavior.
Forms Present
Suspicious number of forms on the page.
JavaScript Form Submission
Javascript form submission is often used to send stolen information.

🔬 Análise Integral de Ameaças

Tipo de Ameaça
Banking Credential Harvester
Alvo
Steam users (International)
Método de Ataque
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Canal de Exfiltração
Form submission (backend endpoint not detected - likely JavaScript-based)
Avaliação de Risco
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 137 obfuscation techniques

🏢 Análise de Falsificação de Marca

Impersonated Brand
Steam
Official Website
https://store.steampowered.com/
Fake Service
Steam Friend Invitation

⚔️ Metodologia de Ataque

Primary Method: Credential Harvesting

The attacker is likely using a fake login form to steal the victim's Steam credentials. The obfuscated Javascript and forms on the page are indicators of this.

🌐 Indicadores de Compromisso de Infraestrutura

🦠 Malicious Files

Main File
prototype-1.7.js?v=npJElBnrEO6W&l=english&_cdn=akamai
File Size

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
2,7 MB

🔗 API Endpoints Detected

Other
78

🔐 Obfuscation Detected

  • : Light
  • : None
  • : Moderate
  • : None
  • : Light
  • : Light
  • : None
  • : None
  • : Light
  • : Light
  • : Light
  • : None
  • : Light
  • : Light
  • : Heavy
  • : Moderate

🤖 AI-Extracted Threat Intelligence

🎯 Malicious Files Identified

Main Drainer
prototype-1.7.js?v=npJElBnrEO6W&l=english&_cdn=akamai
File Size
2780KB

Scan History for s.teams-lc.com

Found 1 other scan for this domain

😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.