EN ES PT
Back to Stats

Visual Capture

Screenshot of bitcoin-eer.com

Detection Info

https://bitcoin-eer.com/
Detected Brand
Bitcoineer AI
Country
International
Confidence
100%
HTTP Status
200
Report ID
79d7fc17-3d8…
Analyzed
2026-02-22 10:28
Final URL (after redirects)
https://bitcoin-eer.com/es/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T10813C83104C46B2B55E343D5A310DA4BE39582C4E376D94BF1EA831A67D5F8ACC2BB9C
CONTENT ssdeep
768:tdz5UkPiUTidCNyiOC+Mr9YlM8cIJ2rkFJcx8rTAwuD/amO/351Jir7TknSClGJj:lUkPiGiq/F9YlTcIJirxrwsbO/J1qMER

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9416ebcac9caca96
VISUAL aHash
fd0606060606fffb
VISUAL dHash
71ccecccecfc3b13
VISUAL wHash
fd0606060606fffb
VISUAL colorHash
0e0000001c0
VISUAL cropResistant
0001496161490152,96d6e8b084710f8e,c030330c3b531333,9cccecccccececec,5c8b26dececec646

Code Analysis

Risk Score 94/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Cryptocurrency investors
• Method: Impersonation and form submission
• Exfil: Account information
• Indicators: Domain name, request for PII.
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • https://bitcoin-eer.com/es/login/

📡 API Calls Detected

  • POST

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain mismatch
The domain does not match the expected official domain of Bitcoineer AI.
Form Submission
Javascript form submission detected to exfiltrate user's information.
Obfuscation
The page uses obfuscation techniques.
Requests sensitive info
The site asks for personal information.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Bitcoineer AI users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking
  • 174 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Bitcoineer AI
Fake Service
Account Sign-up

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The attackers are attempting to harvest user credentials by presenting a fake sign-up form that looks similar to the legitimate website.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
bitcoin-eer.com
Registered
2023-02-01 11:06:36+00:00
Registrar
None
Status
None

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.