EN ES PT
Back to Stats

Visual Capture

Screenshot of noctiscapital.net

Detection Info

https://noctiscapital.net/
Detected Brand
Noctis Capital
Country
International
Confidence
92%
HTTP Status
200
Report ID
d6c6b1ce-339…
Analyzed
2026-08-12 11:17

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1198274B2A040B83B0193C2E6B675636FA3D24689CD87171663FD8B9D0DE3D94FD1A119
CONTENT ssdeep
192:nWa44oCIIoT+BLxe3rL2eCYfWdaLMmTM4zb2mBq:Wa44oBIxe3jPfWdaD4

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c38d3833f6c6c398
VISUAL aHash
000078f8f8f04000
VISUAL dHash
dcd2c2c0c0c08080
VISUAL wHash
0402fefcfcfcf800
VISUAL colorHash
30000000e00
VISUAL cropResistant
a292ee2b2bda82a2,dcd2c2c0c0c08080

Code Analysis

Risk Score 53/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 OTP Stealer

🔬 Threat Analysis Report

• Threat: Financial Investment Scam
• Target: Investors
• Method: Impersonation / Credential Harvesting
• Exfil: Obfuscated JS form submission
• Indicators: New domain, generic corporate copy
• Risk: High

🔒 Obfuscation Detected

  • unescape

📡 API Calls Detected

  • /api/sms-verification-status
  • /api/sms/send
  • POST
  • /api/sms/verify

📊 Risk Score Breakdown

Total Risk Score
92/100

Contributing Factors

Domain Age
Registered less than 30 days ago
Obfuscation
Detection of unescape/obfuscated JS
Suspicious Content
Generic corporate/financial scam language

🔬 Comprehensive Threat Analysis

Threat Type
Two-Factor Authentication Stealer
Target
Noctis Capital users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: OTP Stealer
  • 2 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Noctis Capital
Fake Service
Investment Portal

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Financial Fraud / Credential Harvesting

The site uses a deceptive, high-end financial appearance to build trust, followed by JS-based interception of user input to steal data.

Secondary Method: None

N/A

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
noctiscapital.net
Registered
2026-07-26
Registrar
Unknown
Status
Active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.