EN ES PT
Back to Stats

Captura Visual

Screenshot of ofertas24hofc.shop

Informações de Detecção

https://ofertas24hofc.shop/
Detected Brand
O Boticário
Country
International
Confiança
100%
HTTP Status
200
Report ID
1e36f71f-52b…
Analyzed
2026-02-19 18:58

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1F2F1D8BD01432ABE7577CAA2A660F655E1B742A9DE3B490CF3BD324A1BC5C1884F5170
CONTENT ssdeep
192:ixplDkblgpbl/S2oFePv5ceNLvfVhlfBhlDBhlTBhl6fImF:ixplwbubdS2BPvNzfVvZvdvtv9mF

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9999666699993366
VISUAL aHash
0000181818000000
VISUAL dHash
100c22b2b24c4c30
VISUAL wHash
3c243c3c3c24243c
VISUAL colorHash
07600040000
VISUAL cropResistant
9696aa8e8e862ba2,100c22b2b24c4c30

Análise de Código

Risk Score 73/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Ameaça: Phishing
• Alvo: Clientes O Boticário
• Método: Imitação com questionário
• Exfil: Desconhecido
• Indicadores: Domínio suspeito, logotipo da marca, chamada para ação
• Risco: Alto

🔒 Obfuscation Detected

  • fromCharCode

📡 API Calls Detected

  • /api/lib/utils/handlers/init.php
  • /api/get_public_config.php
  • /product-links.json

📊 Detalhamento da Pontuação de Risco

Total Risk Score
90/100

Contributing Factors

Suspicious Domain
The domain name does not match the legitimate brand's and is recently created.
Brand Impersonation
The site uses the brand's logo and color scheme to appear authentic.
Call to action
The website uses a call to action. Começar desafio

🔬 Análise Integral de Ameaças

Tipo de Ameaça
Banking Credential Harvester
Alvo
O Boticário users (International)
Método de Ataque
Brand impersonation + obfuscated JavaScript
Canal de Exfiltração
Form submission (backend endpoint not detected - likely JavaScript-based)
Avaliação de Risco
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 4 obfuscation techniques

🏢 Análise de Falsificação de Marca

Impersonated Brand
O Boticário
Official Website
https://www.boticario.com.br/
Fake Service
Quiz, Special promotion

Fraudulent Claims

⚔️ Metodologia de Ataque

Primary Method: Brand Impersonation

The attacker creates a website that closely mimics the branding and design of O Boticário to deceive users into thinking they are interacting with the legitimate company. The site then uses offers and promotions to steal personal information.

Secondary Method: Social Engineering

The site aims to take advantage of O Boticário's brand, enticing users with special offers or quizzes to gather personal information such as emails, names, and maybe credit card numbers.

🌐 Indicadores de Compromisso de Infraestrutura

Domain Information

Domínio
ofertas24hofc.shop
Registered
Unknown
Registrar
Unknown
Estado
Active

🤖 AI-Extracted Threat Intelligence

😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.