EN ES PT
Back to Stats

Visual Capture

Screenshot of the-bitcoin-formula-pro-com-gen1.trackfinanceworld.com

Detection Info

https://the-bitcoin-formula-pro-com-gen1.trackfinanceworld.com/
Detected Brand
Bitcoin Formula
Country
International
Confidence
100%
HTTP Status
200
Report ID
ef25cf5d-f58…
Analyzed
2026-02-25 08:30

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T16113423760405A3F12D782C67BB43B4EF3DAD689CA93565667F8830D07C6E80CD31AA6
CONTENT ssdeep
768:0ETm9C+I6hnVlbuVxkYsNjXTeTr/nmk6q:e0+IanVl6VnsXyPmkH

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b239cd4d361c3c47
VISUAL aHash
00ffc7878787ffff
VISUAL dHash
231b0e2c2c3ec8a8
VISUAL wHash
00cf87878703fef8
VISUAL colorHash
07202030000
VISUAL cropResistant
231b2e2c2c3ec8a8,0008046870702004,f0f5bcb9a36958c6

Code Analysis

Risk Score 76/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Cryptocurrency investors
• Method: Credential harvesting
• Exfil: Form data
• Indicators: Unrelated domain, forms, urgency tactic
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode
  • unicode_escape

🎯 Kit Endpoints

  • /login

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Suspicious Domain
The domain name is unrelated to any established trading platform or legitimate financial institution.
Forms Present
The site contains forms for collecting personal information.
Urgency Tactics
The use of 'close registration soon' message
Obfuscation
Obfuscation is often used to hide malicious functionality.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Bitcoin Formula users (International)
Attack Method
credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, Banking, Personal Info
  • 12 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Bitcoin Formula
Fake Service
Trading software

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The site employs a web form designed to collect user data, with the ultimate aim of stealing passwords and personal details. The collected data can be used for financial crimes and identity theft.

Secondary Method: Spear Phishing

The information harvested may be used in later spear phishing attempts, which are more targeted and thus more likely to succeed.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
the-bitcoin-formula-pro-com-gen1.trackfinanceworld.com
Registered
None
Registrar
None
Status
None

🤖 AI-Extracted Threat Intelligence

Similar Websites

Pages with identical visual appearance (based on perceptual hash)

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.