EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

https://tokicas.top
Detected Brand
Tokicas
Country
International
Confidence
100%
HTTP Status
200
Report ID
abd0d11e-ec1…
Analyzed
2026-01-11 03:34
Final URL (after redirects)
https://tokicas.top/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1665419BFA32452F9E106D7DCD962E038326E24FE3B5283A8E7594F36B5148DC8855D83
CONTENT ssdeep
1536:D8Ucshc9BoUpQ5LToi0ZvqLDTKc9BoUpQ5RyiyOYjyty2Byay6K0OWIbZOTeYgLC:zc9HQKc9HQtzK0yNmM6

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
929979a6a66da496
VISUAL aHash
163c5c003e36283c
VISUAL dHash
a4d8d8e4e4c4d8dc
VISUAL wHash
1e3c5c143e7e2c3c
VISUAL colorHash
38006000200
VISUAL cropResistant
727130d2c96b72f2,a4d8d8e4e4c4d8dc

Code Analysis

Risk Score 100/100
Threat Level BAJO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info
WebSocket C2

🔬 Threat Analysis Report

• Threat: Potential data exfiltration from WebSocket
• Target: Tokicas casino players
• Method: Data may be transmitted via WebSocket connections to an external server
• Exfil: Data sent to wss://gambler-work.com/api/ws
• Indicators: WebSocket communication, domain tokicas.top, gambler-work.com domain
• Risk: LOW - Potential unauthorized data transfer, but site not clearly phishing

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • base64_strings

📡 API Calls Detected

  • POST
  • GET
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.