EN ES PT
Back to Stats

Visual Capture

Screenshot of amorimheritagegroup.digital

Detection Info

https://amorimheritagegroup.digital/
Detected Brand
Amorim Heritage Group (Likely fictitious/Investment Scam)
Country
International
Confidence
100%
HTTP Status
200
Report ID
a5adc0f3-70c…
Analyzed
2026-07-20 23:13

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1D2C28671A114273B02B782C9B3A5BB1E66E38249C74B191153FDC36D4BE7E10AE37167
CONTENT ssdeep
768:Ce7Vd0dkK7zsCvA8aV17sOy2+y9BH4c1Ie:3d03stj7sOy2+UBH4c1Ie

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c3469431bc3ce5e5
VISUAL aHash
002430000000ffff
VISUAL dHash
dcc9c0ccc8c8c800
VISUAL wHash
227c7c300060ffff
VISUAL colorHash
39048000e00
VISUAL cropResistant
0880880458988000,dcc9c8e4c8c8c8c8

Code Analysis

Risk Score 76/100
Threat Level ALTO
āš ļø Phishing Confirmed
šŸŽ£ Credential Harvester šŸŽ£ OTP Stealer šŸŽ£ Banking šŸŽ£ Personal Info

šŸ”¬ Threat Analysis Report

• Threat: Investment/Financial Scam
• Target: Financial/Crypto users
• Method: Social engineering via high-tech trading platform promise
• Exfil: User PII via web form
• Indicators: Obfuscated JS, suspicious business claims, marketing disclaimers
• Risk: Critical

šŸ”’ Obfuscation Detected

  • unescape
  • document.write

šŸŽÆ Kit Endpoints

  • login

šŸ“” API Calls Detected

  • /net/register/lax4mf
  • POST

šŸ“Š Risk Score Breakdown

Total Risk Score
95/100

Contributing Factors

Code Obfuscation
Use of unescape/document.write to hide form submission logic
Deceptive Financial Claims
Contradictory disclaimer vs marketing copy
Data Collection
Harvesting PII on non-validated entity

šŸ”¬ Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Amorim Heritage Group (Likely fictitious/Investment Scam) users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

āš ļø Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 8 obfuscation techniques

šŸ¢ Brand Impersonation Analysis

Impersonated Brand
Amorim Heritage Group
Official Website
None
Fake Service
Automated Trading Orchestration

Fraudulent Claims

āš”ļø Attack Methodology

Primary Method: Financial Fraud / Advance Fee

Uses professional UI to appear as a legitimate trading platform, aiming to gather contact information for follow-up investment scams.

Secondary Method: Data Harvesting

Collecting full names, emails, and phone numbers for use in phishing campaigns or sale to other threat actors.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
amorimheritagegroup.digital
Registered
Unknown
Registrar
Unknown
Status
Unknown

šŸ¤– AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.