EN ES PT
Back to Stats

Captura Visual

Screenshot of www.booking-clone-sigma.vercel.app

Informações de Detecção

http://www.booking-clone-sigma.vercel.app/
Detected Brand
Booking.com
Country
Unknown
Confiança
100%
HTTP Status
200
Report ID
32eacfde-f1f…
Analyzed
2026-01-27 11:26
Final URL (after redirects)
https://booking-clone-sigma.vercel.app/

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1FD831BA43909F5271EB343AB20EE1503B378121B940D4D70B254FD9EB6F9C9AA067FD9
CONTENT ssdeep
1536:/pt4z3j8sLx4TESLwsGSMBDLw1j90+1LmjzQ:sz3jsTTwsiW16+1b

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c26bbd446b9194bc
VISUAL aHash
00007e7c347effff
VISUAL dHash
c2c1d8c8e4e4c006
VISUAL wHash
00003c2c347effff
VISUAL colorHash
030000001c0
VISUAL cropResistant
f0c8c9e4c4c022c0,d0c7c0f8c8e0e4d4,02200113814164a4,b0d0d0e0e0e8f8f0,9eebcd8dadf5f5f4

Análise de Código

Risk Score 73/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔒 Obfuscation Detected

  • fromCharCode

📊 Detalhamento da Pontuação de Risco

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected Credential Harvester and OTP Stealer kits targeting Booking.com users for account takeover and payment fraud.
Obfuscation Techniques
Three distinct obfuscation techniques detected, indicating attempts to evade detection and analysis.
Brand Impersonation
Domain and site design mimic Booking.com, a high-value target for credential harvesting and financial fraud.
Form-Based Attack
Two forms detected, likely used for credential harvesting and personal information collection.

🔬 Análise Integral de Ameaças

Tipo de Ameaça
Banking Credential Harvester
Alvo
Booking.com users
Método de Ataque
credential harvesting forms + obfuscated JavaScript
Canal de Exfiltração
Form submission (backend endpoint not detected - likely JavaScript-based)
Avaliação de Risco
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 3 obfuscation techniques

🏢 Análise de Falsificação de Marca

Impersonated Brand
Booking.com
Official Website
https://www.booking.com
Fake Service
Hotel and accommodation booking service

⚔️ Metodologia de Ataque

Primary Method: SERVICE - Credential Harvesting

The phishing kit impersonates Booking.com to trick users into entering their login credentials. The harvested credentials are likely exfiltrated in real-time to the attacker's server for immediate account takeover and unauthorized access to booking history and payment methods.

Secondary Method: SERVICE - OTP Interception

The OTP Stealer kit component captures one-time passwords (OTPs) sent via SMS or authenticator apps. This allows attackers to bypass two-factor authentication and gain full access to victim accounts.

🌐 Indicadores de Compromisso de Infraestrutura

Domain Information

Domínio
www.booking-clone-sigma.vercel.app
Registered
Unknown
Registrar
Unknown
Estado
Hosting platform (subdomain)

🦠 Malicious Files

Main File
File Size

No specific malicious JavaScript files detected, but obfuscation techniques indicate evasion tactics.

📊 Diagrama de Fluxo de Ataque

┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LINK                          │
│    - Email/SMS with fake Booking.com notification         │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM LANDS ON FAKE BOOKING PAGE                     │
│    - Cloned site displays login/booking form             │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT                                      │
│    - User enters Banking/booking credentials             │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA CAPTURE & EXFILTRATION                           │
│    - Form submits credentials via HTTP POST              │
│    - Data sent to attacker-controlled server             │
└──────────────────────────────────────────────────────────┘

🤖 AI-Extracted Threat Intelligence

📊 Attack Flow

┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LINK                          │
│    - Email/SMS with fake Booking.com notification         │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM LANDS ON FAKE BOOKING PAGE                     │
│    - Cloned site displays login/booking form             │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT                                      │
│    - User enters Banking/booking credentials             │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA CAPTURE & EXFILTRATION                           │
│    - Form submits credentials via HTTP POST              │
│    - Data sent to attacker-controlled server             │
└──────────────────────────────────────────────────────────┘

🎯 Malicious Files Identified

😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.