EN ES PT
Back to Stats

Visual Capture

Screenshot of bitql.org

Detection Info

https://bitql.org/
Detected Brand
BitQL
Country
International
Confidence
100%
HTTP Status
200
Report ID
7f090e1c-40b…
Analyzed
2026-02-22 11:45
Final URL (after redirects)
https://bitql.org/es/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1D923E83104C46B6B528343C69350AB1FE39A8144F2BAC59EF2DA872F66C5DC9C877B5C
CONTENT ssdeep
768:uGXdHUx87QDQpGFT5ArdX2PM+T6YggeMuQ6O/RRGJtgEukhmPZ8AcnycsytzpC6L:uGXdHUx87QDQgFFAhm0+T3A/BO/RnS40

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9414ebeac9cac996
VISUAL aHash
fd0606060606ffff
VISUAL dHash
71acccccecec6803
VISUAL wHash
fd0606060604ffff
VISUAL colorHash
0e0000001c0
VISUAL cropResistant
0001495141490152,96d6e8b094710f8e,8020600d6d6c0b13,acacecccccececec

Code Analysis

Risk Score 94/100
Threat Level MEDIO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Cryptocurrency users
• Method: Account creation form with potential data harvesting and obfuscation
• Exfil: Potentially email or phone number.
• Indicators: Forms, obfuscation, JavaScript form submission.
• Risk: Moderate

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • https://bitql.org/es/login/

📡 API Calls Detected

  • POST

📊 Risk Score Breakdown

Total Risk Score
65/100

Contributing Factors

JavaScript Obfuscation
Indicates attempts to hide malicious code.
Account Creation Forms
Common phishing tactic to collect user data.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
BitQL users (International)
Attack Method
obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking
  • 174 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
BitQL
Fake Service
Trading Platform

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The site uses a form to collect personal information (name, email, phone) under the guise of account creation. This information can be used for phishing attacks, spam, or identity theft.

Secondary Method: JavaScript Obfuscation

The use of obfuscated Javascript makes it harder to analyze the site and can be used to hide malicious actions.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
bitql.org
Registered
2020-10-19
Registrar
Namecheap, Inc.
Status
ACTIVE

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.