EN ES PT
Back to Stats

Visual Capture

Screenshot of crestunitfinance.net

Detection Info

https://crestunitfinance.net/
Detected Brand
Crestunit Finance
Country
International
Confidence
100%
HTTP Status
200
Report ID
8c1f9d56-d56…
Analyzed
2026-08-12 23:14

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1BA6256B26154A93782F3C2D7BB25132FB2E34AC9C987065523FD871D8ED2E80EC15D56
CONTENT ssdeep
384:DLPukh6Uq3Ap7Yts4RaCS05HpIIHTpDqXm5RPLMrxwRVXjk7D3eYrW:fSIIJqXm5hgeLqrW

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c3073c3079c7c7c6
VISUAL aHash
00007e7e7efcf8c0
VISUAL dHash
f8f8c0c0c0c02000
VISUAL wHash
00007f7e7efcf8c0
VISUAL colorHash
10000600030
VISUAL cropResistant
f8f8c0c0c0c02000

Code Analysis

Risk Score 71/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Financial Fraud/HYIP
• Target: Investors
• Method: Deceptive corporate landing page with obfuscated scripts
• Exfil: JavaScript form capture
• Indicators: Obfuscated source code, vague financial promises
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode
  • unescape

📡 API Calls Detected

  • POST
  • /api/sms/verify
  • /api/sms/send
  • /api/sms-verification-status

📊 Risk Score Breakdown

Total Risk Score
88/100

Contributing Factors

Obfuscation
Detection of fromCharCode/unescape used to obscure site logic.
Content
HYIP-style hyperbolic language common in investment scams.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Crestunit Finance users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer, Banking
  • 3 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Crestunit Finance
Fake Service
Investment Management

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Financial Fraud / Investment Scam

The site lures users into providing personal or financial data under the guise of an 'exclusive' investment opportunity.

Secondary Method: Credential Harvesting

Form inputs capture sensitive data which is then obfuscated and transmitted to a remote server.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
crestunitfinance.net
Registered
2026-06-09
Registrar
Unknown
Status
Active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.