EN ES PT
Back to Stats

Visual Capture

Screenshot of arb.bot.camp

Detection Info

https://arb.bot.camp/login?next=%2F
Detected Brand
Kraken
Country
International
Confidence
95%
HTTP Status
200
Report ID
66b9d524-515…
Analyzed
2026-03-12 19:01

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T161418B64601C8D37C6C6A5E897E0661A38CDC362CB571B00A7F497DC6BD3F81CE983A6
CONTENT ssdeep
48:NjPrSKq+b8WEQHJ4JudnAIYmUDEQHAGkfHANJL:NvS2b8JJu9AIYmU634TL

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
cc663399cc669933
VISUAL aHash
0000181818180000
VISUAL dHash
1008323232320c10
VISUAL wHash
000038381f1f0f0f
VISUAL colorHash
38000e00000
VISUAL cropResistant
1008323232320c10

Code Analysis

Risk Score 60/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Kraken users
• Method: Impersonation of Kraken login page.
• Exfil: Form data (username, password).
• Indicators: Domain mismatch, Turkish language, Form submission.
• Risk: High

📡 API Calls Detected

  • /login
  • /register

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain Mismatch
The domain arb.bot.camp is not related to the target brand Kraken.
Impersonation
The site mimics the appearance of a Kraken login page.
Language Mismatch
The site uses Turkish language, which may indicate targeting of Turkish-speaking users or a misconfigured/compromised site.

🔬 Comprehensive Threat Analysis

Threat Type
Credential Harvesting Kit
Target
Kraken users (International)
Attack Method
Brand impersonation + credential harvesting forms
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester

🏢 Brand Impersonation Analysis

Impersonated Brand
Kraken
Official Website
kraken.com
Fake Service
Kraken Login

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The attacker aims to steal login credentials by presenting a fake login form that mimics the appearance of the legitimate Kraken login page.

Secondary Method: Social Engineering

The attacker hopes that users will trust the fake login page and enter their credentials.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
arb.bot.camp
Registered
Unknown
Registrar
Unknown
Status
Inactive

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

Scan History for arb.bot.camp

Found 1 other scan for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.