EN ES PT
Back to Stats

Visual Capture

Screenshot of nelvoplatform.com

Detection Info

https://nelvoplatform.com/
Detected Brand
Nelvo
Country
International
Confidence
100%
HTTP Status
200
Report ID
608685bf-e3b…
Analyzed
2026-08-08 11:38

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T115F31A343358793E656383E2F1E67725B17E834BC80F4814F37899B66789C99A823BD4
CONTENT ssdeep
3072:dz0gg2M9EHXEeUnWSA1FpPLXa5H4znV/yNhg9+Tj/mN6ZXt1967+ph:dYqFUnWSA1FpPL+3OSXt1967+ph

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
8da6359d86953d26
VISUAL aHash
0210007e3c181800
VISUAL dHash
e67172f061323008
VISUAL wHash
7a38387f3d3c1c0c
VISUAL colorHash
38003000180
VISUAL cropResistant
fefeff9f4ffffefe,e67172f061323008

Code Analysis

Risk Score 85/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Phishing/HYIP Scam
• Target: Cryptocurrency users
• Method: Obfuscated JS form harvesting
• Exfil: JavaScript-based submission to external host
• Indicators: Obfuscated JS code, 48-day old domain
• Risk: High

🔒 Obfuscation Detected

  • atob
  • fromCharCode
  • unescape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • /login
  • /blog

📡 API Calls Detected

  • /api/platform-settings/

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Code Obfuscation
Detected use of atob/fromCharCode to mask logic.
Domain Age
Domain created < 2 months ago for a 'wealth platform'.
Content/Tactics
HYIP-style promises and multi-level referral structure.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Nelvo users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking
  • 25 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Nelvo
Official Website
N/A
Fake Service
Crypto Investment Platform

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

Uses a fake login portal to capture user credentials or connect malicious dApps to drain crypto wallets.

Secondary Method: HYIP Scam

Lures victims with fake investment returns to solicit direct crypto deposits.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
nelvoplatform.com
Registered
2026-06-21
Registrar
Unknown
Status
Active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.