EN ES PT
Back to Stats

Visual Capture

Screenshot of app.solstsicse.finance

Detection Info

https://app.solstsicse.finance/
Detected Brand
Solstice Finance
Country
International
Confidence
95%
HTTP Status
200
Report ID
c42624ef-c3d…
Analyzed
2026-06-19 23:50

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1AEE3B9362342242E235F07D0B6E0EF6D52ABE245CE578D6E73EC24B19FC9DD09DA5188
CONTENT ssdeep
1536:9d7Owq8T9LF5FXN7jBQ+Cwrayj/z//vW/vs/4hOPJCCcvLSyt73:CwthFXpayvvs5mXcjSyt7

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
dffd66da18259880
VISUAL aHash
80809c9c9c9c8080
VISUAL dHash
2228383838390638
VISUAL wHash
c0dcfe9f9cbcc080
VISUAL colorHash
38000430000
VISUAL cropResistant
00047ab2b2320400,2228383838390638

Code Analysis

Risk Score 59/100
Threat Level ALTO
āš ļø Phishing Confirmed
šŸŽ£ OTP Stealer

šŸ”¬ Threat Analysis Report

• Threat: Cryptocurrency Phishing (Wallet Drainer)
• Target: Solstice Finance users
• Method: Typosquatting/Airdrop scam
• Exfil: Wallet approval/signing
• Indicators: Obfuscated JS code, typosquatted domain
• Risk: Critical

šŸ”’ Obfuscation Detected

  • atob
  • fromCharCode
  • unescape

šŸ“” API Calls Detected

  • POST

šŸ“Š Risk Score Breakdown

Total Risk Score
95/100

Contributing Factors

Typosquatting
Domain uses a letter transposition to impersonate a brand.
Malicious Scripting
Detection of obfuscated drainer code.

šŸ”¬ Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
Solstice Finance users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

āš ļø Indicators of Compromise

  • Kit types: OTP Stealer
  • 12 obfuscation techniques

šŸ¢ Brand Impersonation Analysis

Impersonated Brand
Solstice Finance
Official Website
https://solstice.finance/
Fake Service
Token staking/Airdrops

Fraudulent Claims

āš”ļø Attack Methodology

Primary Method: Crypto Wallet Drainer

The site prompts users to connect their Web3 wallet. Once connected, malicious scripts request permissions to drain tokens or NFTs.

Secondary Method: Typosquatting

Uses a deceptive URL to trick users into thinking they are on the official financial platform.

Target Blockchain
Solana

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
app.solstsicse.finance
Registered
Unknown
Registrar
Unknown
Status
Active

šŸ¤– AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.