EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

https://datryhaex.com/
Detected Brand
Unknown
Country
International
Confidence
100%
HTTP Status
200
Report ID
f86cb806-abb…
Analyzed
2026-08-12 23:15

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1B90373B0E4A0896A064342D1F7F7E75D026DE281DF110CF5A3ED076B9B96E5CA39F209
CONTENT ssdeep
384:YaaCx76j2zXIehUP7nj3ySE+2vDAm4J4PIQjOlXb0IOgInrMEZh0fgg:DaCx7GcXIehkyD1gqb2x

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
c3b43c3cbce5a330
VISUAL aHash
02606e7f6c602060
VISUAL dHash
b6cbc8c8cdc8c0d1
VISUAL wHash
02607effff603070
VISUAL colorHash
02007000000
VISUAL cropResistant
2d4b4b6547644b4b,5511a86c3a657555,5355646d75951b4b,b6cbc8c8cdc8c0d1

Code Analysis

Risk Score 79/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Financial Investment Scam
• Target: Retail Investors
• Method: Phishing/Lead Generation
• Exfil: '/create_lead/'
• Indicators: Obfuscated JS, generic trading claims
• Risk: High

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • unescape
  • unicode_escape
  • base64_strings

📡 API Calls Detected

  • https://modernroomdesigns.com/api/v1/geo
  • POST

📤 Form Action Targets

  • /create_lead/

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Obfuscated Code
Use of unicode_escape/base64 to mask logic
Domain Reputation
Newly registered financial site
Content
High-risk financial scam tropes

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
General public
Attack Method
credential harvesting forms + obfuscated JavaScript
Exfiltration Channel
HTTP POST to backend
Risk Assessment
HIGH - Automated credential harvesting with HTTP POST to backend

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Banking, Personal Info
  • 35 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Datryhaex
Fake Service
Investment Trading Platform

Fraudulent Claims

⚔️ Attack Methodology

Primary Method: Credential Harvesting

Uses deceptive landing pages to capture lead information under the guise of AI trading services.

Secondary Method: Financial Scam/Investment Fraud

Preys on users seeking high returns via automated trading to perform identity theft or deposit solicitation.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
datryhaex.com
Registered
2026-04-27
Registrar
Unknown
Status
active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.