EN ES PT
Back to Stats

Visual Capture

Screenshot of azxlml.com

Detection Info

https://azxlml.com/
Detected Brand
Binance or DeFi related (unclear)
Country
International
Confidence
100%
HTTP Status
200
Report ID
97cad771-905…
Analyzed
2026-02-28 03:29

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1E632BC70548A6E7B10C396E0AB74AF1AF3C68384C7631B18B3F5939E1FD6D0ACD29525
CONTENT ssdeep
96:TUCBf55s5kGyLqm98TJr6NIF8Dl8DrMH8DrhBUm2TijMidDiSi7iK2ieRFTbIbLT:ICBB50/yt981C2QorkcVgKS9

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9959581bb2f2baa2
VISUAL aHash
0000ffffffff5a00
VISUAL dHash
b97035696075b2aa
VISUAL wHash
0000ffffffff0000
VISUAL colorHash
0f003018000
VISUAL cropResistant
0c097308587c7c70,8000c0c280800080,8000c0c0c2008080,39b9b0b0f0d4b032,30318aa2a29229aa

Code Analysis

Risk Score 100/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Phishing/Crypto Scam
• Target: DeFi/Binance users
• Method: Impersonation and enticing DeFi mining
• Exfil: Unclear from screenshot, but probably trying to steal crypto.
• Indicators: Suspicious domain, JavaScript Obfuscation, Binance logo, deceptive content
• Risk: HIGH

🔒 Obfuscation Detected

  • atob
  • fromCharCode
  • unescape
  • document.write
  • hex_escape
  • unicode_escape
  • base64_strings

📡 API Calls Detected

  • GET
  • \u6253\u5370\u7a97\u53e3
  • POST

📊 Risk Score Breakdown

Total Risk Score
95/100

Contributing Factors

Suspicious Domain
The domain is not a known brand and is recently registered
Impersonation
Uses the Binance logo without any verifiable link to the official Binance service.
Obfuscation
JavaScript Obfuscation detected.
Deceptive content
Content designed to lure users into crypto-related scams with promises of high returns.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Binance or DeFi related (unclear) users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 2853 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Binance or a DeFi protocol.
Fake Service
DeFi Node mining, investments

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Impersonation and social engineering

The site mimics a legitimate brand (Binance or DeFi) to gain trust and deceive users.

Secondary Method: Offering investment opportunities which could be a fraudulent crypto mining platform.

The site will likely try to get users to connect a wallet or deposit funds.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
azxlml.com
Registered
2024-03-20
Registrar
Unknown
Status
ACTIVE

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

Scan History for azxlml.com

Found 2 other scans for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.