EN ES PT
Back to Stats

Visual Capture

Screenshot of dorianixfloxin.com

Detection Info

http://dorianixfloxin.com
Detected Brand
Dorianix Floxin
Country
International
Confidence
100%
HTTP Status
200
Report ID
9af2ea1d-eca…
Analyzed
2026-01-30 12:41
Final URL (after redirects)
https://dorianixfloxin.com/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T177B3DD274219692B4477C2D130795F3BE1A5DE8BFAE70A014EECC7F62BF9C90B41A119
CONTENT ssdeep
1536:WGY2pR4nXBKpSpFl26vFRmNwmN84YA/t8P57:uSUMsRmNwmN+

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
de16e9e91c43b641
VISUAL aHash
0000040400fffbff
VISUAL dHash
9eececaca4230333
VISUAL wHash
000004047effffff
VISUAL colorHash
1b402008040
VISUAL cropResistant
808080c0d0808080,808080c0c0808080,808080c0d0c08082,a080b89a9aa88080,004092ccccc40300,c833331333033333,d69cccecececa4a4,6f6e674d19368632,d9090f1f34662e14

Code Analysis

Risk Score 79/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Cryptocurrency trading platform users
• Method: Impersonation and Social Engineering
• Exfil: Form submission, likely steals user data
• Indicators: Domain age, obfuscated JavaScript, form, celebrity testimonial, urgent call to action
• Risk: HIGH

🔒 Obfuscation Detected

  • fromCharCode
  • document.write
  • unicode_escape

📡 API Calls Detected

  • gettup.php?subid5=
  • POST
  • /systems/geo-ip.php

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain Age
Recent domain indicates potential malicious activity.
Obfuscated Javascript
Obfuscation is used to hide malicious code from detection.
Forms Present
Forms on phishing websites harvest user credentials.
Impersonation
The site impersonates a brand/service.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Dorianix Floxin users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking
  • 38 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Dorianix Floxin
Fake Service
Cryptocurrency Trading Platform

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The site uses a form to collect personal information and likely steal credentials, taking advantage of the user's belief that they are interacting with a legitimate financial service.

Secondary Method: Social Engineering

The site uses design elements like a celebrity endorsement to build trust and persuade users to enter their information.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
dorianixfloxin.com
Registered
2023-09-21
Registrar
Unknown
Status
active

🔬 JavaScript Deep Analysis

Operator Language
Portuguese (1%)
Total Code Size
19.5 KB

🔐 Obfuscation Detected

  • : None
  • : None
  • : None

🤖 AI-Extracted Threat Intelligence

Scan History for dorianixfloxin.com

Found 1 other scan for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.