EN ES PT
Back to Stats

Visual Capture

Screenshot of pulavik-savanton.com

Detection Info

https://pulavik-savanton.com/
Detected Brand
Pulavik Savanton (Investment Platform)
Country
International
Confidence
100%
HTTP Status
200
Report ID
59bdbcfb-e39โ€ฆ
Analyzed
2026-08-10 11:19

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T173F3662302186A2E4437C3D175759B76D2B6D98BFAA30A404FDCC7B637EAC50B81B65C
CONTENT ssdeep
1536:9YtUgQmTa3MZo+Hd1+w0Q1jjC3lemF9YYsQOVax0882WRfsSy/:9YtOQ2b3tvYhWW8822ty/

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c61be4bb2d83932c
VISUAL aHash
fd1c1c3811bff3f3
VISUAL dHash
19b4fcf1632a2727
VISUAL wHash
fd1c1c100197f3f3
VISUAL colorHash
07000180003
VISUAL cropResistant
19b4fcf1632a2727,0000808880c80000

Code Analysis

Risk Score 83/100
Threat Level ALTO
โš ๏ธ Phishing Confirmed
๐ŸŽฃ Credential Harvester ๐ŸŽฃ OTP Stealer ๐ŸŽฃ Banking

๐Ÿ”ฌ Threat Analysis Report

โ€ข Threat: Financial Investment Phishing
โ€ข Target: Users looking for trading platforms
โ€ข Method: Impersonation of a fake AI trading firm
โ€ข Exfil: Form data POST to /send
โ€ข Indicators: Obfuscated JS, suspicious domain, non-existent entity claims
โ€ข Risk: High

๐Ÿ” Credential Harvesting Forms

๐Ÿ”’ Obfuscation Detected

  • unicode_escape

๐ŸŽฏ Kit Endpoints

  • /send
  • /blog

๐Ÿ“ก API Calls Detected

  • https://ipapi.co/json/
  • /subid

๐Ÿ“ค Form Action Targets

  • /send

๐Ÿ“Š Risk Score Breakdown

Total Risk Score
95/100

Contributing Factors

Obfuscated JavaScript
Detection of unicode_escape to hide malicious logic.
Investment Fraud Pattern
Claims 4M+ users on a 60-day old domain; clear investment scam indicator.

๐Ÿ”ฌ Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Pulavik Savanton (Investment Platform) users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
HTTP POST to backend
Risk Assessment
CRITICAL - Automated credential harvesting with HTTP POST to backend

โš ๏ธ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking
  • 31 obfuscation techniques

๐Ÿข Brand Impersonation Analysis

Impersonated Brand
Pulavik Savanton
Fake Service
Investment Platform

Fraudulent Claims

โš”๏ธ Attack Methodology

Primary Method: Credential Harvesting / Data Collection

The site uses a deceptive form to capture PII from victims under the guise of an investment registration process.

Secondary Method: Identity Fraud

The site requests name, email, and phone, likely for targeted secondary phishing attacks or data selling.

๐ŸŒ Infrastructure Indicators of Compromise

Domain Information

Domain
pulavik-savanton.com
Registered
2026-06-10
Registrar
N/A
Status
Active

๐Ÿค– AI-Extracted Threat Intelligence

๐Ÿ˜ฐ
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.