EN ES PT
Back to Stats

Visual Capture

Screenshot of presightaiprofit.net

Detection Info

https://presightaiprofit.net/
Detected Brand
Unknown / Financial Investment Scam
Country
International
Confidence
90%
HTTP Status
200
Report ID
208fd065-636…
Analyzed
2026-08-12 23:21

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T14FC265B31108583E5197878ED262333DE2B35E93DE5FB52051AA4F3689D3E41DD1B23A
CONTENT ssdeep
192:pel+MJqo1xiL26IIXqK/S8Kro1uc1jAWI9AxIkZcOJWkXda8GE1WyikLfSbBfZB9:pelNds9IIRxXXxIkYUhGE1xikLfSbb

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c99696696d2ab389
VISUAL aHash
fcfcfcf0f9e9f87c
VISUAL dHash
1bf4e02393d383c4
VISUAL wHash
d87cfcf0f8e07060
VISUAL colorHash
07003000180
VISUAL cropResistant
1bf4e02393d383c4

Code Analysis

Risk Score 53/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer

🔬 Threat Analysis Report

• Threat: Financial Investment Fraud
• Target: General Public
• Method: Social Engineering/Fake AI Trading platform
• Exfil: Obfuscated JavaScript form submission
• Indicators: High-yield promise text, generic AI buzzwords
• Risk: High

🔒 Obfuscation Detected

  • unescape

📡 API Calls Detected

  • /api/sms-verification-status
  • POST
  • /api/sms/verify
  • /api/sms/send

📊 Risk Score Breakdown

Total Risk Score
85/100

Contributing Factors

JavaScript Obfuscation
Detected obfuscated script used for form handling.
Suspicious Content
Unverifiable claims of high-yield AI investment.
Domain Maturity
Domain age is relatively low for a financial firm.

🔬 Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
Unknown / Financial Investment Scam users (International)
Attack Method
obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer
  • 2 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
N/A
Fake Service
AI Investment/Trading

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Financial Investment Fraud

The site lures users with high-yield financial promises to collect PII (Personally Identifiable Information) for future scams.

Secondary Method: Data Harvesting

Uses obfuscated JS to send collected form inputs to an external server.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
presightaiprofit.net
Registered
2026-06-01
Registrar
Unknown
Status
active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.