EN ES PT
Back to Stats

Visual Capture

Screenshot of paragonixearn.app

Detection Info

https://paragonixearn.app/
Detected Brand
Paragonix Earn
Country
International
Confidence
100%
HTTP Status
200
Report ID
f5c4d51c-e15…
Analyzed
2026-02-25 04:56
Final URL (after redirects)
https://paragonixearn.app/es/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T15823D87104C47B7B47D393C59300EA4FE3998044B67AC68EF9E6C79E2686DD4C836A6C
CONTENT ssdeep
768:9oYOPA0LQ2W/mpC+un0Bc8LRZbNQXd6fmF5eDyB+A2ZZBGg3IDxeLM9FI:9oYOPFE/6TBc8LRZZQXd6fmF56yB+Ayz

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
956ae9b0ceea8790
VISUAL aHash
ff0000006e6e4e7e
VISUAL dHash
71f0c4e0dcdc9cd4
VISUAL wHash
ff1800007e7e4e7e
VISUAL colorHash
02000000030
VISUAL cropResistant
0001816363c90006,928fcb8a8e86848c,84c4e0b0885e988e,53c08390e0301cc6,30994ec3e1606468,b0d4d0ccdcdc9cd4

Code Analysis

Risk Score 94/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Traders
• Method: Imitation of a trading platform with account creation.
• Exfil: Javascript form submission
• Indicators: Obfuscation and request of Personal Data
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • https://paragonixearn.app/es/login/

📡 API Calls Detected

  • POST

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

JavaScript Obfuscation
Indicates attempts to hide malicious code or exfiltration tactics.
Form Data Collection
The site collects personal data that is not necessary to offer its claimed services.
Domain Suspicion
The domain name, combined with the other indicators, is suspicious

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Paragonix Earn users (International)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
CRITICAL - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking
  • 174 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Paragonix Earn (Assumed)
Fake Service
Trading platform

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The site uses a form to collect personal information with the goal of obtaining user credentials or other identifying information.

Secondary Method: Potential investment scam

The site may be a prelude to a cryptocurrency investment scam targeting the user once they create an account.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
paragonixearn.app
Registered
Unknown
Registrar
Unknown
Status
Active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.