EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

https://airdrop.bankofvector.com/
Detected Brand
Unknown
Country
International
Confidence
100%
HTTP Status
200
Report ID
bcc177e6-83a…
Analyzed
2026-02-27 17:26

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T10222833161911A3F496BCBE8B1B8F32A65AEC31EC92BC059F6DC43721BCBD01DD12588
CONTENT ssdeep
192:aWvZunTYzgyes6YvYipkzaRZJ/YhOlrusJ/:ZhunTY+YvYWk2lYqus9

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c1a13f2dc5352de1
VISUAL aHash
03047e7e78780000
VISUAL dHash
caac92d0d0c00000
VISUAL wHash
026f7e7e7878e0c0
VISUAL colorHash
11007000000
VISUAL cropResistant
caac92d0d0c00000

Code Analysis

Risk Score 100/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info
WebSocket C2

🔬 Threat Analysis Report

• Threat: Phishing attack
• Target: Cryptocurrency users
• Method: Malicious airdrop tool
• Exfil: wss://relay.walletconnect.org, wss://rpc.vscblockchain.org
• Indicators: Domain mismatch, JavaScript Obfuscation, Form present
• Risk: High

🔒 Obfuscation Detected

  • atob
  • fromCharCode
  • unescape
  • unicode_escape
  • base64_strings

📡 API Calls Detected

  • POST

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain Suspicion
Domain name does not align with a known legitimate service. Domain age is relatively low.
JavaScript Obfuscation
Detected JavaScript obfuscation, a common technique used by attackers to hide malicious code. Uses atob, fromCharCode, and unescape.
Form with Sensitive Data
The site has forms asking for wallet details. This could be used for malicious purposes and theft.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
General public
Attack Method
credential harvesting forms + real-time WebSocket exfiltration + obfuscated JavaScript
Exfiltration Channel
WebSocket (2 endpoints)
Risk Assessment
CRITICAL - Automated credential harvesting with WebSocket (2 endpoints)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 207 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
BANK (likely not legit)
Fake Service
Airdrop tool

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Wallet phishing/Malicious airdrop

The site pretends to be a tool for airdropping tokens. It prompts users to connect their wallets and input wallet addresses and amounts, which could lead to unauthorized access to funds or the stealing of private keys.

Target Blockchain
Vector Smart Chain

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
airdrop.bankofvector.com
Registered
2024-08-16
Registrar
Unknown
Status
Active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.