EN ES PT
Back to Stats

Visual Capture

Screenshot of web3walletconnect.digital

Detection Info

https://web3walletconnect.digital/
Detected Brand
Unknown
Country
International
Confidence
100%
HTTP Status
200
Report ID
d7f98dd1-fdb…
Analyzed
2026-03-19 14:48

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1C38319A43A59F5A65AF3439310DF1403B378562B140D4D20A350ECAE76BDC9BA0B7FDA
CONTENT ssdeep
1536:g8nvQTVq53QlHxh8N6R8XXhjaPnQWT+muEpc:g8nvQTj/mN6yXt1IS

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
996666999966899b
VISUAL aHash
0000181818180000
VISUAL dHash
00083232b2320c10
VISUAL wHash
00003c3c1c1c0000
VISUAL colorHash
38007000000
VISUAL cropResistant
00083232b2320c10

Code Analysis

Risk Score 79/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Unspecified
• Method: Credential Harvesting
• Exfil: Potentially via JavaScript to an unknown location.
• Indicators: Unrelated domain, JavaScript obfuscation and form submission.
• Risk: High

🔒 Obfuscation Detected

  • atob
  • fromCharCode
  • unicode_escape

📡 API Calls Detected

  • /api/notify-telegram

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain mismatch
Domain name does not relate to any known brand.
JavaScript obfuscation and Form Submission
Javascript Obfuscation detected alongside a form submission. This is used by attackers to hide malicious code that steals user data.
Generic Login Form
Use of a generic login prompt.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
General public
Attack Method
credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking
  • 10 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Unknown
Fake Service
Unknown

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The site uses a form to trick users into providing credentials, likely by mimicking a login page. This is a common phishing technique.

Secondary Method: JavaScript Obfuscation

JavaScript is obfuscated to hide potentially malicious code, such as code for credential theft or redirecting the user.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
web3walletconnect.digital
Registered
Unknown
Registrar
Unknown
Status
Inactive

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.