EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

http://app-token.click
Detected Brand
Coinlib
Country
International
Confidence
100%
HTTP Status
200
Report ID
c23492ec-4f7…
Analyzed
2026-01-01 20:25
Final URL (after redirects)
https://app-token.click/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1ED6273B0E064473B27C783E297735E5EB2E561F4CA66069597F887A48EC7EE0DE12310
CONTENT ssdeep
384:BeWdhq1u8oZmkyySky06kybVoB5N/kkykCDky1D0Dkyb5cm8N1lg8:kWdh1y6y8yGyiypy587x

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c89d16f17c71706c
VISUAL aHash
013d1959f9f1f070
VISUAL dHash
73e1f3b3b3d5c5c5
VISUAL wHash
013d1979f9f1f070
VISUAL colorHash
30000e00000
VISUAL cropResistant
73e1f3b3b3d5c5c5

Code Analysis

Risk Score 86/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Cryptocurrency wallet drainer / credential harvesting phishing kit.
• Target: Users of various cryptocurrency wallets.
• Method: Lures users to "sync" or "validate" their wallets on a fake website to steal private keys or credentials.
• Exfil: Data exfiltration via obfuscated JavaScript using atob and fromCharCode.
• Indicators: Suspicious domain `app-token.click`, ambiguous language about wallet syncing, promises of secure server connections, obfuscated javascript.
• Risk: CRITICAL - Potential for immediate cryptocurrency theft.

🔒 Obfuscation Detected

  • atob
  • fromCharCode

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

Scan History for app-token.click

Found 2 other scans for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.