EN ES PT
Back to Stats

Visual Capture

Screenshot of dmdotfun.info

Detection Info

https://dmdotfun.info/
Detected Brand
dm.fun
Country
International
Confidence
100%
HTTP Status
200
Report ID
2e3a37dd-551…
Analyzed
2026-08-02 11:48

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T18E232237B30415B94E638FD8B8139F5090BEE229D103B16CD36CD6365AE6CA3F56D60A
CONTENT ssdeep
384:iw2NjaNlnKGhD+nthvvv9sDVwGrobmi3HV3qLh5fuH8zQcOMaRL96KO:iwkaNlnKGhD+nzX1sDmGrobmi3HfzbNO

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
89dc7163673465cc
VISUAL aHash
403c3f003c780020
VISUAL dHash
9671b24ac0d0d8d8
VISUAL wHash
c0ff3f3f7c682020
VISUAL colorHash
38002408000
VISUAL cropResistant
9671b24ac0d0d8d8

Code Analysis

Risk Score 73/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Crypto Wallet Drainer
• Target: Solana users
• Method: Fake Airdrop/Allocation claim
• Exfil: Malicious smart contract interaction
• Indicators: Obfuscated JS, urgent claim interface
• Risk: Critical/Asset theft

🔒 Obfuscation Detected

  • unescape

📡 API Calls Detected

  • POST

📊 Risk Score Breakdown

Total Risk Score
98/100

Contributing Factors

Impersonation
Uses brand identity for malicious intent
Technical
Detected obfuscated JS for drainer
Domain
Non-official TLD for project

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
dm.fun users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer, Banking, Personal Info
  • 2 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
dm.fun
Official Website
https://dm.fun
Fake Service
Token Allocation Claim

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Wallet Draining

Prompts users to connect their Web3 wallet and sign malicious transactions to steal assets.

Secondary Method: Brand Impersonation

Copies the UI/UX of a legitimate crypto project to build false confidence.

Target Blockchain
Solana

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
dmdotfun.info
Registered
Unknown
Registrar
Unknown
Status
active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.