EN ES PT
Back to Stats

Visual Capture

Screenshot of andinamonetiv.com

Detection Info

https://andinamonetiv.com/
Detected Brand
Andina Monetiv
Country
International
Confidence
90%
HTTP Status
200
Report ID
65cfb6b8-c62…
Analyzed
2026-08-12 23:11

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T10D6275F310805E3742A3D3C5E662633BE1D282C8EDCB524957FE8B1A4AE5E90FD29517
CONTENT ssdeep
192:WrSoX3w44mnx0GptOtyufvQ9XgZRM55tVr4F9uR7yF:WrSJ442zOOwZCVrY9a7yF

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c3c76c383891e747
VISUAL aHash
00707c7e60202030
VISUAL dHash
d0c5c0c8c8ccc2c2
VISUAL wHash
20f0fefe7e700078
VISUAL colorHash
38007000000
VISUAL cropResistant
d0c5c0c8c8ccc2c2

Code Analysis

Risk Score 53/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer

🔬 Threat Analysis Report

• Threat: Investment Fraud / HYIP
• Target: Financial/Crypto investors
• Method: Social engineering via high-yield promises
• Exfil: Obfuscated JS form submission
• Indicators: Unrealistic return claims, no verified history
• Risk: High

🔒 Obfuscation Detected

  • unescape

📡 API Calls Detected

  • /api/sms-verification-status
  • /api/sms/send
  • POST
  • /api/sms/verify

📊 Risk Score Breakdown

Total Risk Score
85/100

Contributing Factors

JavaScript Obfuscation
Detection of unescape obfuscation indicates an intent to hide malicious code.
Fraudulent Content Pattern
Investment platform making high-yield, low-risk promises without regulatory transparency.

🔬 Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
Andina Monetiv users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer
  • 2 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Andina Monetiv
Fake Service
Investment Platform

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Financial Fraud / HYIP

The site lures victims with promises of high-yield AI-managed crypto investments. It utilizes obfuscated JS to handle form data, likely funneling data to a collection server.

Secondary Method: Social Engineering

Building false legitimacy through professional web design and buzzwords to gain user trust.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
andinamonetiv.com
Registered
2026-03-09
Registrar
unknown
Status
active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.