EN ES PT
Back to Stats

Visual Capture

Screenshot of 8282usdt.com

Detection Info

https://8282usdt.com/
Detected Brand
Upbit (Impersonation)
Country
South Korea
Confidence
90%
HTTP Status
200
Report ID
7783d9ba-f6d…
Analyzed
2026-07-28 23:34

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T10582B9B070829772005383E1BA61BFAE92D1E24DE6570940DEFFC76A4EF9C45EC1A15B
CONTENT ssdeep
384:Wn47tNyBjjFxZDe8sWdCTA1wf8qd4LLQ7:c47tNyBjhu20MCf8omLs

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
9203ed12d26dc5ed
VISUAL aHash
0004000e0e0cffff
VISUAL dHash
f7fdd8dcdcfcef30
VISUAL wHash
070f000e0e0effff
VISUAL colorHash
02002000180
VISUAL cropResistant
ffefcfc7c7cf7fb6,fffb2d2c2c6df7ff,b86f67b8b0a888aa,ef0080324032321a,f6fddcdcdcdcfcfd,7fdf9fefcfcfaf5f

Code Analysis

Risk Score 65/100
Threat Level ALTO
āš ļø Phishing Confirmed
šŸŽ£ Credential Harvester
WebSocket C2

šŸ”¬ Threat Analysis Report

• Threat: Financial/Crypto Fraud
• Target: South Korean Crypto Investors
• Method: Impersonation of exchange tools
• Exfil: User credentials/transaction data
• Indicators: Unofficial crypto exchange wrapper
• Risk: High

šŸŽÆ Kit Endpoints

  • /login.php

šŸ“” API Calls Detected

  • /api/markets.php?t=

šŸ“Š Risk Score Breakdown

Total Risk Score
85/100

Contributing Factors

Impersonation
Uses Upbit market data to masquerade as an authorized exchange service.
Domain Reputation
Newish domain used for financial services.

šŸ”¬ Comprehensive Threat Analysis

Threat Type
Credential Harvesting Kit
Target
Upbit (Impersonation) users (South Korea)
Attack Method
Brand impersonation + real-time WebSocket exfiltration
Exfiltration Channel
WebSocket (1 endpoints)
Risk Assessment
HIGH - Automated credential harvesting with WebSocket (1 endpoints)

āš ļø Indicators of Compromise

  • Kit types: Credential Harvester

šŸ¢ Brand Impersonation Analysis

Impersonated Brand
Upbit
Official Website
https://upbit.com
Fake Service
Crypto Exchange/OTC

Fraudulent Claims

āš”ļø Attack Methodology

Primary Method: Financial Impersonation

The site creates a false sense of security by integrating real-time market data from legitimate exchanges (Upbit), tricking users into believing it is a reliable OTC trading platform.

Secondary Method: Credential Harvesting

Users are required to register and login, allowing attackers to collect credentials.

Target Blockchain
Tether (USDT)

🌐 Infrastructure Indicators of Compromise

Domain Information

Domain
8282usdt.com
Registered
2026-05-13
Registrar
Unknown
Status
Active

šŸ¤– AI-Extracted Threat Intelligence

😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.