EN ES PT
Back to Stats

Visual Capture

Screenshot of oilevexpro.org

Detection Info

https://oilevexpro.org/
Detected Brand
Oil Evex Pro
Country
International
Confidence
100%
HTTP Status
200
Report ID
592ea9b8-4ac…
Analyzed
2026-02-24 10:37
Final URL (after redirects)
https://oilevexpro.org/es/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1BE13D83158C46B7B02C383D15364AE1BF3E69284E27ACB0AF6E6935B56C4D54CC37A6C
CONTENT ssdeep
768:oxZdXsWI7xkndBsN8gfxzzke0w5kAKRYVkT6wsNGw3fCcEDON5nGTPDLSnQMHFJZ:oxXcnwBE15n2w+AKRokT61NGwPCinGLK

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
944be9948eb4e2cb
VISUAL aHash
ff000016360606ff
VISUAL dHash
71f1ecececac8c31
VISUAL wHash
ff000636366606ff
VISUAL colorHash
03000000038
VISUAL cropResistant
0001416363c50004,2428787858787878,96d6e8b0904d0f8e,f8f8b8f8e92c3c68,00000034347c012d,32d0ececece4ac8c

Code Analysis

Risk Score 94/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Impersonation phishing.
• Target: Users interested in Oil Evex Pro.
• Method: Forms to steal credentials.
• Exfil: User-entered data.
• Indicators: Account creation form, trading platform theme, obfuscated JS.
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • https://oilevexpro.org/es/login/

📡 API Calls Detected

  • POST

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

JavaScript Obfuscation
Javascript obfuscation hides malicious activity.
Recent Domain Age
A newly created domain is a common indicator of phishing.
Form for credentials
A registration/login form is used to steal credentials.
Impersonation
The site mimics a financial service.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Oil Evex Pro users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking
  • 174 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Oil Evex Pro
Fake Service
Trading platform

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The attacker aims to steal user credentials (username, password) by luring them into entering this information into a fake form that closely resembles the legitimate login page of Oil Evex Pro.

Secondary Method: Malicious JavaScript Injection

Obfuscated Javascript can be used to redirect the user to a different site, steal entered data, or redirect to a more sophisticated phishing page. This can lead to further attacks.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
oilevexpro.org
Registered
2023-08-23
Registrar
None
Status
None

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.