EN ES PT
Back to Stats

Captura Visual

Screenshot of avertron.net

Informações de Detecção

http://avertron.net
Detected Brand
Avertron AI
Country
Belgium
Confiança
95%
HTTP Status
200
Report ID
f82abab8-7b2…
Analyzed
2026-01-26 13:42
Final URL (after redirects)
https://avertron.net/

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1E0D2723460C5A9270887B2D1F7761B5BB7A09340D253870992FCCB5E2FD3C98DD2A5B4
CONTENT ssdeep
384:HjkTddTPsutWl+N8E1Pqu3IgKMmw084N59Iy55ym/sRANb8wYTFo3iWJg:H/ur1PJ3IgKhR8m59v/VNbnYGc

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
da34e9e9345a9469
VISUAL aHash
0000060606fff9ff
VISUAL dHash
92cc9cac9c233b23
VISUAL wHash
000006060fffffff
VISUAL colorHash
1b002000180
VISUAL cropResistant
a080a07060c080a0,a28098da5a9080aa,808088fa3ab880b2,9200b8badaf80042,0411ea9292ca1582,9b00332b3b330323,921ecc8c9cacac98,317978b93c3c7a7e

Análise de Código

Risk Score 66/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer

🔬 Threat Analysis Report

• Ameaça: Phishing de golpe de investimento em criptomoedas
• Alvo: Cidadãos belgas interessados em negociação de criptomoedas
• Método: Um site enganoso promete lucros diários garantidos através de negociação automatizada de IA, coletando informações pessoais através de um formulário de inscrição.
• Exfil: Dados enviados para validation/thankyou.php (potencialmente API personalizada)
• Indicadores: Domínio novo, alegações de lucro irrealistas, exfiltração de dados de formulário e táticas de urgência.
• Risco: ALTO - Potencial perda financeira e roubo de identidade.

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • document.write
  • unicode_escape

📡 API Calls Detected

  • https://ipapi.co/json
  • https://ipapi.co/json/
  • /validation/style.php
  • POST

📤 Form Action Targets

  • validation/thankyou.php

📊 Detalhamento da Pontuação de Risco

Total Risk Score
90/100

Contributing Factors

Active Phishing Kit
Detected OTP Stealer kit with form interception capabilities targeting personal information and potential OTP theft.
High Obfuscation
32 obfuscation techniques detected in JavaScript files, indicating deliberate evasion of detection.
Urgency and Reward Tactics
Uses high-reward claims (€975 daily benefit) and urgency (only 38 spots remaining) to manipulate victims.
Suspicious Domain
Domain avertron.net is not associated with the official Avertron AI brand and lacks legitimate infrastructure (no IPs or nameservers detected).
Form-Based Credential Harvesting
Single form detected with fields for first name, last name, and email, likely used for credential harvesting.

🔬 Análise Integral de Ameaças

Tipo de Ameaça
Two-Factor Authentication Stealer
Alvo
Avertron AI users (Belgium)
Método de Ataque
credential harvesting forms + obfuscated JavaScript
Canal de Exfiltração
HTTP POST to backend
Avaliação de Risco
HIGH - Automated credential harvesting with HTTP POST to backend

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer
  • 32 obfuscation techniques

🏢 Análise de Falsificação de Marca

Impersonated Brand
Avertron AI
Official Website
https://www.avertron.ai
Fake Service
Exclusive daily financial benefit for Belgian citizens

Fraudulent Claims

⚔️ Metodologia de Ataque

Primary Method: Credential Harvesting with OTP Interception

The phishing kit is designed to harvest personal information (first name, last name, email) via a web form. Given the kit type (OTP Stealer), it likely intercepts one-time passwords (OTPs) sent to victims via SMS or email, enabling attackers to bypass 2FA protections on compromised accounts.

Secondary Method: Social Engineering (Reward and Urgency Tactics)

The campaign employs psychological manipulation by promising a daily benefit of €975 and creating urgency with a limited number of spots (38 remaining). This tactic pressures victims into submitting their personal information without critical evaluation.

🌐 Indicadores de Compromisso de Infraestrutura

Domain Information

Domínio
avertron.net
Registered
2026-01-26 09:40:29+00:00
Registrar
PDR Ltd. d/b/a PublicDomainRegistry.com
Estado
Recently registered (0 days old)

🦠 Malicious Files

Main File
File Size

Contains obfuscated code likely used for form interception and credential harvesting.

📊 Diagrama de Fluxo de Ataque

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. INITIAL COMPROMISE                                    │
│    - Victim receives phishing link                       │
│    - Redirects to fake Avertron AI Banking page          │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. CREDENTIAL COLLECTION                                 │
│    - Victim enters login credentials                     │
│    - Fake page captures input                            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. OTP INTERCEPTION                                      │
│    - Fake page requests one-time password                │
│    - Victim enters OTP code                              │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION                                     │
│    - Collected credentials sent via HTTP POST            │
│    - Standard form submission to attacker server         │
└──────────────────────────────────────────────────────────┘
```

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
58,4 KB

🔗 API Endpoints Detected

Other
5

🔐 Obfuscation Detected

  • : None
  • : None
  • : None
  • : Light

🤖 AI-Extracted Threat Intelligence

📊 Attack Flow

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. INITIAL COMPROMISE                                    │
│    - Victim receives phishing link                       │
│    - Redirects to fake Avertron AI Banking page          │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. CREDENTIAL COLLECTION                                 │
│    - Victim enters login credentials                     │
│    - Fake page captures input                            │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. OTP INTERCEPTION                                      │
│    - Fake page requests one-time password                │
│    - Victim enters OTP code                              │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION                                     │
│    - Collected credentials sent via HTTP POST            │
│    - Standard form submission to attacker server         │
└──────────────────────────────────────────────────────────┘
```

🎯 Malicious Files Identified

Scan History for avertron.net

Found 1 other scan for this domain

😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.