EN ES PT
Back to Stats

Visual Capture

Screenshot of bitcoinsuperstar.io

Detection Info

https://bitcoinsuperstar.io/
Detected Brand
Bitcoin Superstar (likely fake)
Country
International
Confidence
100%
HTTP Status
200
Report ID
e01b5b37-518…
Analyzed
2026-02-22 11:17
Final URL (after redirects)
https://bitcoinsuperstar.io/es/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1A523C83160C46B275AB382C193509F9BE3958184EA7AC95FF5DB831B1B84D9CCC37A8D
CONTENT ssdeep
1536:RwwOPFwC7eJdNBav03kYnfmH4iXgjQBqmY22lgki:RvOP2j3R2ai

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
916ab8b1eeeb9490
VISUAL aHash
ff0000006e6e4e4e
VISUAL dHash
71f0dce0dcdc9cdc
VISUAL wHash
ff0030007e7e4e7e
VISUAL colorHash
02000000030
VISUAL cropResistant
0021416363490006,d28fcbcb8e8ec694,84c4c0b4a00e1c88,53c08390e0301cc6,5c4ea36064585a31,32d4d0e8dcdc9cdc

Code Analysis

Risk Score 94/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Cryptocurrency traders
• Method: Imitates a trading platform to collect personal data.
• Exfil: Data is likely sent to an unknown location.
• Indicators: JavaScript obfuscation, form submission, brand impersonation
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • https://bitcoinsuperstar.io/es/login/

📡 API Calls Detected

  • POST

📊 Risk Score Breakdown

Total Risk Score
85/100

Contributing Factors

Active Phishing Kit
Presence of a registration form and potential for data exfiltration.
JavaScript Obfuscation
Indicates attempts to hide malicious code.
Domain Age
The domain is not new but it's not a known brand, could be associated with a new project or scam.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Bitcoin Superstar (likely fake) users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking
  • 174 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Bitcoin Superstar
Fake Service
Bitcoin trading platform

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The site uses a registration form to collect personal information (name, email, phone number) under the guise of a Bitcoin trading platform. This information can be used to spear-phish, target other scams, or is sold to other threat actors.

Secondary Method: Malware distribution

JavaScript may be obfuscated and serve as a redirect or download a malware payload.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
bitcoinsuperstar.io
Registered
2019-10-03
Registrar
Namecheap, Inc.
Status
ACTIVE

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.