EN ES PT
Back to Stats

Visual Capture

Screenshot of beattmertlgiin.webflow.io

Detection Info

https://beattmertlgiin.webflow.io/
Detected Brand
BitMart
Country
International
Confidence
95%
HTTP Status
200
Report ID
e9ea7c9c-111…
Analyzed
2026-02-02 11:27

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1E54156B7D02C1C5613A583ACB671B48C8D43259F8B87AC49E5D8F46EA36DBD301524DD
CONTENT ssdeep
48:Q/mxIzDtXTbAp6BxCVeXLSmm+u/iYLhlZntyehlZnt2ohlZntjhlZntYghlZntUn:Q/mxIzDtjbAOCVcLSp/aYLhlryehlr2j

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
afd06b6ad02fd00b
VISUAL aHash
ffff3fffdfa101f7
VISUAL dHash
8967473330636b0b
VISUAL wHash
7d33379fd70100c3
VISUAL colorHash
07000000c00
VISUAL cropResistant
8967473330636b0b,ce86c60616660e26,9c9effaaeafffdff,3b31e6e6361e0626

Code Analysis

Risk Score 56/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester

🔬 Threat Analysis Report

• Threat: Phishing
• Target: BitMart users
• Method: Impersonation through a look-alike site hosted on free hosting.
• Exfil: Potentially stealing credentials and financial data.
• Indicators: Free hosting with brand logo, obfuscation detected.
• Risk: HIGH

🔒 Obfuscation Detected

  • fromCharCode
  • unicode_escape

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Free Hosting
The site is hosted on a free platform, a common indicator of phishing.
Brand Impersonation
The site is designed to look like a legitimate BitMart page, attempting to steal credentials.
Obfuscation
Obfuscation is used in the javascript

🔬 Comprehensive Threat Analysis

Threat Type
Credential Harvesting Kit
Target
BitMart users (International)
Attack Method
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
MEDIUM - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester
  • 19 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
BitMart
Official Website
null
Fake Service
BitMart

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The attacker aims to steal user credentials by creating a fake login page that mimics the BitMart website. Users entering their email/phone and password will have their credentials stolen. Then the attackers would gain access to BitMart accounts.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
beattmertlgiin.webflow.io
Registered
None
Registrar
None
Status
None

🔬 JavaScript Deep Analysis

Sophistication Level
Basic
Total Code Size
36.5 KB

🔗 API Endpoints Detected

Other
4
Backend API
1

🔐 Obfuscation Detected

  • : Light

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

Scan History for beattmertlgiin.webflow.io

Found 2 other scans for this domain

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.