EN ES PT
Back to Stats

Visual Capture

Screenshot of m.lifinity-dex.com

Detection Info

https://m.lifinity-dex.com/
Detected Brand
1inch
Country
International
Confidence
98%
HTTP Status
200
Report ID
9809a452-137…
Analyzed
2026-08-05 23:48

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T17DB285B3A0C27D3702B7E1D296B6937B71D6814DC9774960A3FC83AD67C0D90A96A343
CONTENT ssdeep
384:KhNw0503svrUUHTeAn/g8SD/6YmlNWJkz/Dwg8W3oFhrKNH3lJs54i:GSsQUHTXn/g8Y6YmHWmzbwghoFhrKNH4

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
8cab23ac8b8eae33
VISUAL aHash
8100183c18181000
VISUAL dHash
6310617032b03000
VISUAL wHash
ff3c3c3c3c3c0000
VISUAL colorHash
38000000e00
VISUAL cropResistant
6310617032b03000

Code Analysis

Risk Score 59/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer

🔬 Threat Analysis Report

• Threat: Brand Impersonation/Wallet Drainer
• Target: 1inch Network users
• Method: Typosquatting/Impersonation site
• Exfil: Malicious JS payload via obfuscated scripts
• Indicators: Mismatched domain, very young registration
• Risk: High - Funds theft

🔒 Obfuscation Detected

  • eval
  • unicode_escape
  • base64_strings

📊 Risk Score Breakdown

Total Risk Score
95/100

Contributing Factors

Domain Age
Domain is only 14 days old.
Brand Impersonation
Direct visual copy of 1inch.
Malicious Code
Detection of obfuscated exfiltration scripts.

🔬 Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
1inch users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer
  • 122 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
1inch
Official Website
https://1inch.io
Fake Service
DEX Aggregator

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Wallet Drainer

The site uses a malicious 'Connect Wallet' button to trigger a Web3 interaction that asks the user to sign a malicious transaction, allowing the attacker to transfer tokens out of the user's wallet.

Secondary Method: Typosquatting/Impersonation

Hosting on a domain that appears semi-professional ('lifinity-dex') to deceive users into believing it is a legitimate decentralized exchange interface.

Target Blockchain
Ethereum/EVM-compatible

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
lifinity-dex.com
Registered
2026-07-22
Registrar
Unknown
Status
Active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.