EN ES PT
Back to Stats

Captura Visual

Screenshot of credfacilitadora.netlify.app

Informações de Detecção

https://credfacilitadora.netlify.app/
Detected Brand
Shopee
Country
Unknown
Confiança
100%
HTTP Status
200
Report ID
b3da307b-121…
Analyzed
2026-01-26 11:12

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T14102A635524E0D3F7103D6A5F2A4777A006AA34FD66F8404F1B90663D6CBECAE827578
CONTENT ssdeep
96:nGHFA1cgx+M73sQ8egsBP146ftUn1o+Mk7EIfyFN4kIwPUNHZkxeJrak88oakXMg:11N6k4ohwv5WTowthzOIz3

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b35d4c73194c6659
VISUAL aHash
00ffffffefe7ffff
VISUAL dHash
144c3014484d3222
VISUAL wHash
0040dbc3c8c0d8d8
VISUAL colorHash
07000038000
VISUAL cropResistant
4c0834524c4d3222,0000343430340800

Análise de Código

Risk Score 100/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • base64_strings

📡 API Calls Detected

  • GET
  • https://ipapi.co/json/

📊 Detalhamento da Pontuação de Risco

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected Credential Harvester, OTP Stealer, Card Stealer, and Banking kits with real-time interception capabilities.
High Obfuscation
161 obfuscation techniques detected, indicating deliberate evasion of static analysis.
Malicious JavaScript Files
Presence of large (1.1 MB) JavaScript files (fbevents.js, pixel.js, latest.js) with no legitimate purpose identified.
Brand Impersonation
Impersonation of Shopee, a high-value e-commerce target for credential and payment theft.

🔬 Análise Integral de Ameaças

Tipo de Ameaça
Banking Credential Harvester
Alvo
Shopee users
Método de Ataque
obfuscated JavaScript
Canal de Exfiltração
Unknown
Avaliação de Risco
CRITICAL - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 161 obfuscation techniques

🏢 Análise de Falsificação de Marca

Impersonated Brand
Shopee
Official Website
https://www.shopee.com
Fake Service
Fake Shopee account verification or promotion

⚔️ Metodologia de Ataque

Primary Method: Credential Harvesting

The phishing kit captures Shopee user credentials via a fake login portal. Input fields are intercepted in real-time and exfiltrated to attacker-controlled infrastructure.

Secondary Method: OTP and Payment Data Theft

The kit includes modules to steal one-time passwords (OTP) and credit card details, enabling account takeover and unauthorized transactions. Payment data is likely validated client-side before exfiltration.

🌐 Indicadores de Compromisso de Infraestrutura

Domain Information

Domínio
credfacilitadora.netlify.app
Registered
Unknown
Registrar
Unknown
Estado
Active (age unknown)

🦠 Malicious Files

Main File
File Size

Large JavaScript file with no legitimate functionality detected, likely used for credential and payment data exfiltration.

📊 Diagrama de Fluxo de Ataque

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. INITIAL CONTACT                                       │
│    - Victim receives phishing message (email/SMS)        │
│    - Message contains link to fake Shopee page           │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE PAGE DISPLAY                                     │
│    - Victim visits counterfeit Shopee login page         │
│    - Page mimics legitimate Banking portal               │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL CAPTURE                                    │
│    - Victim enters login credentials                     │
│    - Fake form collects sensitive information            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA TRANSMISSION                                     │
│    - Collected data sent via HTTP POST                   │
│    - Standard form submission to attacker-controlled     │
│      destination                                         │
└──────────────────────────────────────────────────────────┘
```

🔬 JavaScript Deep Analysis

Operator Language
Portuguese (1%)
Sophistication Level
Basic
Total Code Size
1,1 MB

🔗 API Endpoints Detected

Other
44

🔐 Obfuscation Detected

  • : Light
  • : Moderate
  • : Light
  • : Light
  • : Heavy

🤖 AI-Extracted Threat Intelligence

📊 Attack Flow

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. INITIAL CONTACT                                       │
│    - Victim receives phishing message (email/SMS)        │
│    - Message contains link to fake Shopee page           │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. FAKE PAGE DISPLAY                                     │
│    - Victim visits counterfeit Shopee login page         │
│    - Page mimics legitimate Banking portal               │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL CAPTURE                                    │
│    - Victim enters login credentials                     │
│    - Fake form collects sensitive information            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA TRANSMISSION                                     │
│    - Collected data sent via HTTP POST                   │
│    - Standard form submission to attacker-controlled     │
│      destination                                         │
└──────────────────────────────────────────────────────────┘
```

🎯 Malicious Files Identified

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.