Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T177A24635660152AB03BB95C0F6607E2EB1D3F30FC506C656ABBD918A1FC3CB5BB22561 |
|
CONTENT
ssdeep
|
384:TmSchQch2FgF5FLFYF0CF6EFUFyVClCwFF:Tm4Abxo0G6scyVCn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccccc6666663333 |
|
VISUAL
aHash
|
3018183018181018 |
|
VISUAL
dHash
|
2432302030302030 |
|
VISUAL
wHash
|
38183c383c183c3c |
|
VISUAL
colorHash
|
38003200040 |
|
VISUAL
cropResistant
|
2432302030302030 |
• Threat: Phishing
• Target: KuCoin users
• Method: Domain spoofing and potential credential harvesting via forms and javascript obfuscation
• Exfil: Potentially via websocket URLs, with the possibility of malicious javascript exfiltrating sensitive data
• Indicators: Recent domain, cryptocurrency price info, obfuscated Javascript, and websocket URLs.
• Risk: High
The site likely uses a convincing login form that redirects users to a credential-stealing back-end. The javascript obfuscation is used to hide the malicious nature of the form's backend.
The malicious javascript code, once executed, could capture or redirect login information, browser information or even deploy crypto malware.
Pages with identical visual appearance (based on perceptual hash)