EN ES PT
Back to Stats

Visual Capture

Screenshot of epstn-event.fun

Detection Info

http://epstn-event.fun
Detected Brand
Unknown (Jeffrey Epstein related)
Country
International
Confidence
95%
HTTP Status
200
Report ID
5167c390-643…
Analyzed
2026-02-01 11:20
Final URL (after redirects)
https://epstn-event.fun/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T17452A7A26154302F212B89CB5F29676C31B760BFDEB70241BBECC785D79AD40FD0A545
CONTENT ssdeep
384:N03RZ6KgDqcOx0ARZ6pnzGxCevxGPB0F8:6BZ6KgDqlOKZ6NGx3O

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
92928c6d6de49e96
VISUAL aHash
7e6c2c6400180018
VISUAL dHash
f4cccdc9d278b270
VISUAL wHash
ff7e7c6c003c1838
VISUAL colorHash
31e00000000
VISUAL cropResistant
f4cccdc9d278b270

Code Analysis

Risk Score 3/100
Threat Level ALTO
⚠️ Phishing Confirmed

🔬 Threat Analysis Report

• Threat: Cryptocurrency Scam
• Target: Users interested in crypto airdrops
• Method: Deceptive website promoting a fake airdrop.
• Exfil: Unknown, likely to be connected to crypto wallet.
• Indicators: New domain, unusual topic, airdrop, obfuscation.
• Risk: High

🔒 Obfuscation Detected

  • atob

🎯 Kit Endpoints

  • #blog

📡 API Calls Detected

  • https://lite-api.jup.ag/price/v3?ids=
  • POST

📊 Risk Score Breakdown

Total Risk Score
95/100

Contributing Factors

Recent Domain
Domain created recently is a strong phishing indicator.
Unusual Topic
Combination of Epstein name and airdrop is highly suspicious
Obfuscation
Obfuscation detected using atob suggests an attempt to hide malicious code.
Airdrop
Airdrops can be used to trick users and potentially steal funds.

🔬 Comprehensive Threat Analysis

Threat Type
Unknown (Jeffrey Epstein related) Phishing Landing Page
Target
Unknown (Jeffrey Epstein related) users (International)
Attack Method
obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
LOW - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • 36 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
None (unbranded, Epstein name used)
Fake Service
Crypto Airdrop

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Social Engineering

The site leverages the notoriety of Jeffrey Epstein and the allure of free crypto tokens to entice users into interacting with the site.

Secondary Method: Potential Malicious Smart Contract Interaction

Users might be asked to connect their wallets to claim the airdrop which could lead to theft of funds or approval of malicious contracts.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
epstn-event.fun
Registered
None
Registrar
Unknown
Status
ACTIVE

🔬 JavaScript Deep Analysis

Operator Language
English (1%)
Total Code Size
11.4 KB

🔗 API Endpoints Detected

Other
4
Discord Webhooks
1

🔐 Obfuscation Detected

  • : Light
  • : None

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.