EN ES PT
Back to Stats

Visual Capture

Screenshot of bitalphaai.app

Detection Info

https://bitalphaai.app/
Detected Brand
BitAlpha AI
Country
International
Confidence
100%
HTTP Status
200
Report ID
e3715fc7-5f8…
Analyzed
2026-02-22 10:13
Final URL (after redirects)
https://bitalphaai.app/es/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T16C23FA3114C46B2B968343C9A351EA0FE3968104E279D65AF2D9C72E97C6EC9CC3F758
CONTENT ssdeep
768:kO4jUPdMRBvGwniBmpPYzpMV7nh573suzOW3dkEC8CXcklvHZysm808CuOXAgfK3:kO4QVMRcBmpAzyDh578uzOWNkv/cofZ1

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9449eb948eb4e2cb
VISUAL aHash
ff000016360606ff
VISUAL dHash
71f3ecececac8c39
VISUAL wHash
ff000636366606ff
VISUAL colorHash
03000000038
VISUAL cropResistant
0001416363490004,2428787858787878,96d6e8b0904d0f8e,f8f8b8f8e92c3c68,0000001d3d6c012d,30f1ececece4ac8c

Code Analysis

Risk Score 94/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Cryptocurrency investors
• Method: Form submission
• Exfil: Unknown (likely database or third-party service)
• Indicators: Obfuscated JavaScript, suspicious domain, form collection
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • https://bitalphaai.app/es/login/

📡 API Calls Detected

  • POST

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Obfuscated Javascript
Presence of obfuscated Javascript code used to hide malicious intentions
Form submission to collect PII
The website asks for PII through an registration form.
Domain Age
The domain is new and suspicious for the claims.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
BitAlpha AI users (International)
Attack Method
obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking
  • 174 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
BitAlpha AI
Fake Service
BitAlpha AI (Trading Platform)

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The website attempts to harvest user information by enticing users to sign up for investment opportunities. The signup form requests name, email and phone number, which can be used to send more phishing attempts or sold to third parties.

Secondary Method: Malware Injection

The site potentially injects malicious scripts through Javascript obfuscation.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
bitalphaai.app
Registered
Unknown
Registrar
Unknown
Status
Inactive/Unknown

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.