EN ES PT
Back to Stats

Visual Capture

Screenshot of trezor-recover.com

Detection Info

http://trezor-recover.com
Detected Brand
Trezor
Country
International
Confidence
100%
HTTP Status
200
Report ID
8e642e86-7d2…
Analyzed
2026-01-21 12:19
Final URL (after redirects)
https://trezor-recover.com/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1A352A662234876BF52D7CEFDB4A2F3766126D14AD1B3C1C8A3FC45B65BC2C59C912290
CONTENT ssdeep
192:7eCYqQSv44FfhrL2hdgkrrrTpdRDXnAdE+ZjWbKu:a7qQSv44FfhrL2hdgMTj+ZjWbKu

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
8707d69e18d1d31b
VISUAL aHash
0600000001ffffff
VISUAL dHash
fcc6d272730c4d4c
VISUAL wHash
0e2000000fffffff
VISUAL colorHash
0fe02000000
VISUAL cropResistant
de9ebacecebaba9e,b2534dac364dcda6,b0c1e0606141c48e,790e18304d0c08d0,fceec6c2dad673f9

Code Analysis

Risk Score 73/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Credential harvesting phishing kit
• Target: Trezor hardware wallet users
• Method: Fake wallet recovery page stealing recovery phrases
• Exfil: Data sent via JavaScript form submission
• Indicators: Recent domain, domain mismatch, obfuscated JavaScript
• Risk: CRITICAL - Real-time theft of recovery phrases

🔒 Obfuscation Detected

  • fromCharCode

📡 API Calls Detected

  • /api/recovery-submissions

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.