EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

https://heltruvizantrade.com/
Detected Brand
Unknown
Country
International
Confidence
100%
HTTP Status
200
Report ID
ab6f134b-2bd…
Analyzed
2026-08-12 23:17

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T19A42A6B2A0106B3B0273D2C57722237DE2A3818CD58615552BEE874F1DE7F82DD2A54B
CONTENT ssdeep
192:mXQ0VQ62L13uH644834MAi5GPnVVqOcVXEkzKOmU4iJ6a:l0F+j448341QETOmUKa

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
f1b7ce88b3308cc6
VISUAL aHash
fffecfc7cfc84070
VISUAL dHash
0e041c98989091c0
VISUAL wHash
ffe0eec7ccc06060
VISUAL colorHash
07c00018000
VISUAL cropResistant
0e041c98989091c0

Code Analysis

Risk Score 68/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Financial Scam/Investment Fraud
• Target: General Public
• Method: Deceptive landing page with obfuscated JS
• Exfil: Unknown backend
• Indicators: Obfuscated JS, vague corporate branding
• Risk: High

🔒 Obfuscation Detected

  • unescape

📡 API Calls Detected

  • POST
  • /api/sms/verify
  • /api/sms/send
  • /api/sms-verification-status

📊 Risk Score Breakdown

Total Risk Score
85/100

Contributing Factors

JavaScript Obfuscation
Use of unescape/obfuscated code
Recent Domain
Domain age under 3 months
Content
Lack of identifiable business details

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
General public
Attack Method
obfuscated JavaScript
Exfiltration Channel
Unknown
Risk Assessment
HIGH - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer, Banking
  • 2 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Heltruvizan
Fake Service
Investment/Finance

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Scam Landing Page

Uses deceptive marketing copy and obfuscated scripts to lure users into interacting with a fake platform.

Secondary Method: Credential Harvesting

Hidden forms capture input data sent to external servers.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
heltruvizantrade.com
Registered
2026-06-11
Registrar
Unknown
Status
Active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.