EN ES PT
Back to Stats

Visual Capture

Screenshot of directpatrimonor.com

Detection Info

https://directpatrimonor.com/
Detected Brand
Unknown/Investment Scam
Country
International
Confidence
90%
HTTP Status
200
Report ID
aeedf42b-b6f…
Analyzed
2026-08-12 23:15

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1478285B5B1456D3B82D3C2C2F771B72BE3938285DD8B6618B3F9971A4DC1E81CC1906A
CONTENT ssdeep
192:fnyv22fq7s44KnI2Ai7mP1k2vsGhgch6IoAas2f/TXamvTvWvLO:fnC22944aIib2vScwyLO

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c3e738388e47c333
VISUAL aHash
00207c747c60003c
VISUAL dHash
d041c8c0ccc23171
VISUAL wHash
00e1fefe7e70003c
VISUAL colorHash
38c00000000
VISUAL cropResistant
d041c8c0ccc23171

Code Analysis

Risk Score 53/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer

🔬 Threat Analysis Report

• Threat: Financial Investment Fraud
• Target: Retail investors
• Method: AI-powered trading lure
• Exfil: Form data submission
• Indicators: Generic investment branding
• Risk: Critical financial loss

🔒 Obfuscation Detected

  • unescape

📡 API Calls Detected

  • POST
  • /api/sms/send
  • /api/sms-verification-status
  • /api/sms/verify

📊 Risk Score Breakdown

Total Risk Score
85/100

Contributing Factors

Content Analysis
High-risk investment claims typical of fraud.
Technical
Obfuscated JS detected on landing page.

🔬 Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
Unknown/Investment Scam users (International)
Attack Method
obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer
  • 2 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Direct Patrimonor
Fake Service
Automated Investment Platform

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Investment Scam

Promising unrealistic financial returns via an AI trading bot to induce victims to register and deposit assets.

Secondary Method: Credential Harvesting

Phishing form collects user registration data for contact by scammers.

Target Blockchain
Not specified

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
directpatrimonor.com
Registered
2026-03-16
Registrar
Unknown
Status
active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.