EN ES PT
Back to Stats

Visual Capture

Screenshot of bitcoin-everest.net

Detection Info

https://bitcoin-everest.net/
Detected Brand
Bitcoin Everest
Country
International
Confidence
92%
HTTP Status
200
Report ID
39a712a8-373…
Analyzed
2026-08-12 23:12

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1AB6254B69102A93F11F3C1D2A621AB3F72E6914DDA4B0B0653FC4B2D4BC6DA0FC25599
CONTENT ssdeep
192:wVsBilI0IINBXf3myiCBdtE5kMEzmc8T5c3/7MNR3PZR/37:usBgxII/3m70DE9zW3jA3PDj

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c68cb8b086cfe1bc
VISUAL aHash
ff000074266000ff
VISUAL dHash
2f34cbc4c4cc2340
VISUAL wHash
ff000076767700ff
VISUAL colorHash
30000e40000
VISUAL cropResistant
c029292f2f2929c4,0000000000000000,4133c8c4cccd2340

Code Analysis

Risk Score 53/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer

🔬 Threat Analysis Report

• Threat: Crypto Wallet Drainer
• Target: Cryptocurrency users
• Method: Social engineering via 'AI Trading' tool
• Exfil: JavaScript form/webhook submission
• Indicators: Obfuscated JS, rapid token sniping claims
• Risk: Critical financial loss

🔒 Obfuscation Detected

  • unescape

📡 API Calls Detected

  • POST
  • /api/sms/verify
  • /api/sms/send
  • /api/sms-verification-status

📊 Risk Score Breakdown

Total Risk Score
95/100

Contributing Factors

Malicious Scripting
Obfuscated JS patterns identified
Deceptive Content
Crypto-sniping/drainer themes
Domain Indicators
Short domain history and niche crypto usage

🔬 Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
Bitcoin Everest users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer
  • 2 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Bitcoin Everest
Official Website
N/A
Fake Service
AI Crypto Trading Terminal

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Wallet Drainer

The site uses a deceptive interface to trick users into connecting their Web3 wallets. Once connected, malicious scripts attempt to prompt the user to sign a fraudulent transaction or approve token transfers.

Secondary Method: Credential Harvesting

Forms designed to capture wallet information or API keys under the guise of setting up an AI trading terminal.

Target Blockchain
Ethereum

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
bitcoin-everest.net
Registered
2026-03-16
Registrar
Unknown
Status
active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.