EN ES PT
Back to Stats

Visual Capture

Screenshot of damarketslimited.com

Detection Info

https://damarketslimited.com/
Detected Brand
DA Markets
Country
International
Confidence
100%
HTTP Status
200
Report ID
1686130c-993…
Analyzed
2026-08-24 11:24

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T14FF36238A300053E55574BE8F3E4A33C51BAE388DA17891DB67C01A21BC7EE5EE67794
CONTENT ssdeep
1536:bxUIkBpoLojuqjV3U3uPHwzFa0zn/ztodfXmsBhK6yr:bxSBWUfXmsBoNr

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c1e73c3cc7e1301e
VISUAL aHash
020c7c7c7c4c0c0c
VISUAL dHash
c678c8c8e898d878
VISUAL wHash
420c7e7c7c7c3c1c
VISUAL colorHash
30000000e00
VISUAL cropResistant
c678c8c8e898d878

Code Analysis

Risk Score 76/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Financial Credential Harvesting
• Target: DA Markets users
• Method: Impersonation of trading platform
• Exfil: JavaScript-based form submission
• Indicators: Obfuscated source code
• Risk: High (Financial theft)

🔒 Obfuscation Detected

  • fromCharCode
  • unescape

📡 API Calls Detected

  • /api/content
  • POST
  • /api/market-quotes
  • /world-map.json

📊 Risk Score Breakdown

Total Risk Score
88/100

Contributing Factors

Obfuscated Code
Use of fromCharCode/unescape
Domain Impersonation
Close name match to official brand
Form Submission
Detected JS form handler

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
DA Markets users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 3 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
DA Markets
Official Website
https://damarkets.com
Fake Service
Forex/Trading Platform

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The site mimics a legitimate broker platform to trick users into entering personal and banking data.

Secondary Method: Data Exfiltration via JS

Uses obfuscated JS to intercept form submissions and send them to an external server.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
damarketslimited.com
Registered
2026-03-13
Registrar
Unknown
Status
active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.