EN ES PT
Back to Stats

Visual Capture

Screenshot of gaingeneratorpro.net

Detection Info

https://gaingeneratorpro.net/
Detected Brand
Gain Generator Pro
Country
International
Confidence
100%
HTTP Status
200
Report ID
a630e952-91c…
Analyzed
2026-02-23 08:16
Final URL (after redirects)
https://www.gaingeneratorpro.net/en/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T10D4387338154A4370533C3C4767A1B3AD392864FD7A30A415AFC83EFBBD5CA19A6B169
CONTENT ssdeep
768:pvj3wlJhBWV6VeLi65K1QCbNWY03RHxhScj7:JrwlJhqK/qK1QCbNWY0h6cj7

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b115e66b483f4770
VISUAL aHash
007e0e0e0e008fff
VISUAL dHash
d8dc581818181f06
VISUAL wHash
007e8e8e8e808fff
VISUAL colorHash
02213000000
VISUAL cropResistant
dcd85c18181b1f04,00b086d292ad90c8,d64e8fa72182d293

Code Analysis

Risk Score 100/100
Threat Level ALTO
āš ļø Phishing Confirmed
šŸŽ£ Credential Harvester šŸŽ£ OTP Stealer šŸŽ£ Banking šŸŽ£ Personal Info

šŸ”¬ Threat Analysis Report

• Threat: Phishing
• Target: Users interested in investments.
• Method: Forms to steal personal data.
• Exfil: Potentially to partners for investment education or other malicious use.
• Indicators: Forms, consent for data sharing, focus on finance.
• Risk: High

šŸ”’ Obfuscation Detected

  • atob
  • fromCharCode
  • unicode_escape
  • base64_strings

šŸŽÆ Kit Endpoints

  • /staticfiles/gaingeneratorpro.net/logo.png?v=20
  • https://www.gaingeneratorpro.net/staticfiles/gaingeneratorpro.net/logo-400.png?v=120

šŸ“” API Calls Detected

  • POST
  • https://www.google.com/ccm/geo

šŸ“Š Risk Score Breakdown

Total Risk Score
80/100

Contributing Factors

Active Phishing Kit
Forms and data requests indicate active phishing attempt.
Obfuscated JavaScript
Use of obfuscation techniques increases the risk of malicious activity

šŸ”¬ Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Gain Generator Pro users (International)
Attack Method
credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

āš ļø Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 219 obfuscation techniques

šŸ¢ Brand Impersonation Analysis

Impersonated Brand
Gain Generator Pro
Fake Service
Trading Solution

Fraudulent Claims

āš”ļø Attack Methodology

Primary Method: Credential Harvesting

The site employs a form to collect user's personal information (name, email and phone number), which can be used to perform more phishing attacks or identity theft.

Secondary Method: Malware distribution (possible)

JavaScript obfuscation may be used to hide malicious code.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
gaingeneratorpro.net
Registered
None
Registrar
None
Status
None

šŸ¤– AI-Extracted Threat Intelligence

Scan History for gaingeneratorpro.net

Found 1 other scan for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.