EN ES PT
Back to Stats

Visual Capture

Screenshot of app.btrustsave.org

Detection Info

https://app.btrustsave.org/
Detected Brand
Bancorp Trust Savings
Country
USA
Confidence
100%
HTTP Status
200
Report ID
f8febab4-8be…
Analyzed
2026-02-27 19:35

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T12453233C63C1573550CB87B2E5949F29D29DCBD9DF27AD8BF2ACD2471A8AC448F42260
CONTENT ssdeep
768:X/YFf8q7RobfXHwo4xBg281EVNx1v3PZBGEWbDjfdeHYV:ifJ7xlx1v3P2EWb9

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
a9abd0b2c2ead2d2
VISUAL aHash
ff0b0b1303030100
VISUAL dHash
dbd7d3d3d7d79b90
VISUAL wHash
ff1b1b3b1303035a
VISUAL colorHash
07600008040
VISUAL cropResistant
ebdfd3d3d3d7d7b3,2040838b73a36393,dfd3d3d3d7d39a90

Code Analysis

Risk Score 79/100
Threat Level ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Phishing
• Target: Bancorp Trust Savings users
• Method: Domain spoofing, javascript obfuscation.
• Exfil: Likely credential harvesting.
• Indicators: Domain mismatch, obfuscated javascript, suspicious domain.
• Risk: High

🔒 Obfuscation Detected

  • fromCharCode
  • unescape
  • unicode_escape

🎯 Kit Endpoints

  • https://app.btrustsave.org/send-money
  • https://app.btrustsave.org/login
  • https://app.btrustsave.org/verify

📡 API Calls Detected

  • https://libretranslate.com/translate
  • POST

📊 Risk Score Breakdown

Total Risk Score
90/100

Contributing Factors

Domain Mismatch
The domain does not belong to the brand being impersonated.
Javascript Obfuscation
Code obfuscation is a common technique used to hide malicious code, such as keyloggers or credential stealers.

🔬 Comprehensive Threat Analysis

Threat Type
Banking Credential Harvester
Target
Bancorp Trust Savings users (USA)
Attack Method
Brand impersonation + obfuscated JavaScript
Exfiltration Channel
Form submission (backend endpoint not detected - likely JavaScript-based)
Risk Assessment
HIGH - Automated credential harvesting with Form submission (backend endpoint not detected - likely JavaScript-based)

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer, Card Stealer, Banking, Personal Info
  • 9 obfuscation techniques

🏢 Brand Impersonation Analysis

Impersonated Brand
Bancorp Trust Savings
Fake Service
Banking Services

⚔️ Attack Methodology

Primary Method: Credential Harvesting

The attacker likely aims to steal user credentials. The site may redirect to a login page or present a form for data entry. The javascript obfuscation is intended to hide malicious actions.

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
app.btrustsave.org
Registered
None
Registrar
Unknown
Status
Active

🤖 AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.