EN ES PT
Back to Stats

Captura Visual

Screenshot of rebrand.ly

Informações de Detecção

https://rebrand.ly/ux86de6
Detected Brand
PayPal
Country
International
Confiança
100%
HTTP Status
200
Report ID
faa0d1dd-d58…
Analyzed
2026-02-10 00:37
Final URL (after redirects)
https://www.paypal.com/us/home

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1FD44C2785918AC2E0641848DE1CF3798B15FC24A8B0247ABB36B2D7F87E14B7757C663
CONTENT ssdeep
1536:r3OOtc2B1U1g14yHJ4BHp2c3or502X2y2/HiHplFXWXHiuH31VxUgoC1wIUF:r3BOAGVup8c

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
f08ad28b74a9de70
VISUAL aHash
ffe7c3c3c3ffc2c0
VISUAL dHash
59482a9696695c54
VISUAL wHash
ff204343c3ffc0c0
VISUAL colorHash
01007000000
VISUAL cropResistant
59482a9696695c54,69e48d6b8b8ad232,0555a9a93763b9ac,44946c69b2967175,12326226995bc9c9,d9999ae56515d5d5,3979f8a8ade9a3b1,33ccac4cce9c8c63

Análise de Código

Risk Score 85/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Ameaça: Phishing
• Alvo: Usuários do PayPal
• Método: Redirecionamento de URL e engenharia social
• Exfil: A ofuscação de JavaScript pode indicar exfiltração de dados. A URL final após o redirecionamento é desconhecida, portanto, a localização também é desconhecida.
• Indicadores: Encurtador de URL, personificação, ofuscação de javascript, envio de formulários javascript.
• Risco: ALTO

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • document.write
  • unicode_escape
  • js_packer
  • base64_strings

🎯 Kit Endpoints

  • /us/digital-wallet/send-receive-money/send-money?locale.x=en_US
  • https://www.paypal.com/us/digital-wallet/send-receive-money/pool-money
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/PricingCardTableRebrand-e59d1e27.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/NavBanner-0e476819.js
  • https://www.msmaster.qa.paypal.com/contentmanager
  • https://www.paypalobjects.com/pa/3pjs/tl/6.4.157/patlcfg.js
  • https://www.paypalobjects.com/pa/3pjs/glassbox/detector-dom.min.js
  • https://adobe.ly/3sHgQHb
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/ScrollStickyButton-96dc9211.js
  • https://www.paypalobjects.com/globalnav/js/main-BptD1Wyh.js
  • https://www.youtube-nocookie.com/embed/${e}?autoplay=1&rel=0&autohide=2&border=0&wmode=opaque&showinfo=0&hd=1&playsinline=1&enablejsapi=1`,Ib=new
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/TabControllerGridItem-852a7038.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/OfferCardType-b73c43dd.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/TextHeaderInner-f693b97a-e1cf33fc.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/SplitGraphicSectionType-d7cd9e7a.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/SubNav-a0064f0b.js
  • /us/digital-wallet/send-receive-money?locale.x=en_US
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/index-8ae288e1-584fb91f.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/AppDownloadGroup-811742a7.js
  • /us/digital-wallet/send-receive-money/request-money?locale.x=en_US
  • https://www.datadoghq-browser-agent.com
  • https://www.paypalobjects.com/helpcenter/smartchat/sales/v1/open-chat.js
  • https://ddbm2.paypal.com/js/
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/PpReactCurrencyInput-35f9b855-92d02e2b.js
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/TabControllerGridItem-7ffc6555-e845d5af.js
  • https://www.paypal.com/us/digital-wallet/send-receive-money/send-money
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/Spacer-6ff81921.js
  • /us/digital-wallet/send-receive-money/pool-money?locale.x=en_US
  • https://www.paypalobjects.com/pa/3pjs/tl/6.4.65/patleaf.js
  • http://a
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/useStickyElementHeight-0dbaade3-a1416799.js
  • https://ns.adobe.com/personalization/redirect-item
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/FeatureColumnType-033e0a90.js
  • /us/digital-wallet/send-receive-money/start-selling?locale.x=en_US
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/CurrencyListSection-0eebced6.js
  • http://test/path
  • https://www.paypalobjects.com/ppcmsnodeweb/pp-com-components/BrandSplashSection-6310d414.js
  • /us/digital-wallet/send-receive-money/giving?locale.x=en_US
  • https://www.paypal.com/us/digital-wallet/send-receive-money/request-money

📡 API Calls Detected

  • POST
  • post
  • GET
  • get

📊 Detalhamento da Pontuação de Risco

Total Risk Score
90/100

Contributing Factors

Active Phishing Kit
URL Shortener combined with impersonation of a well-known brand and Javascript obfuscation indicate the presence of an active phishing campaign.
Impersonation
The page mimics the design of a legitimate PayPal page, increasing the chances of users falling victim to the phishing scam.
Suspicious Code
Javascript obfuscation and the presence of javascript form submissions.

🔬 Análise Integral de Ameaças

Tipo de Ameaça
Banking Credential Harvester
Alvo
PayPal users (International)
Método de Ataque
Brand impersonation + obfuscated JavaScript
Canal de Exfiltração
Form submission (backend endpoint not detected - likely JavaScript-based)
Avaliação de Risco
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 730 obfuscation techniques

🏢 Análise de Falsificação de Marca

Impersonated Brand
PayPal
Official Website
paypal.com
Fake Service
PayPal website

⚔️ Metodologia de Ataque

Primary Method: Credential Harvesting

The attacker aims to steal user credentials by redirecting them to a fake login page that mimics PayPal's legitimate site. Javascript obfuscation and form submission detection suggest the use of javascript to harvest and send the user's data to a malicious server.

Secondary Method: Redirection

The use of rebrand.ly is a method of hiding the malicious destination. The redirect is a form of social engineering.

🌐 Indicadores de Compromisso de Infraestrutura

🦠 Malicious Files

Main File
mktconf.js
File Size

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Sophistication Level
Basic
Total Code Size
1,8 MB

🔗 API Endpoints Detected

Other
175

🔐 Obfuscation Detected

  • : Moderate
  • : Light
  • : Moderate
  • : Heavy
  • : Light
  • : None
  • : Light
  • : None
  • : None
  • : Light
  • : None
  • : Light

🤖 AI-Extracted Threat Intelligence

🎯 Malicious Files Identified

Main Drainer
mktconf.js
File Size
1843KB

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.