Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12022B81FD24C222207D18B95BD9A27C9F71A401C23928FDD6C78909C73B97585F762EB |
|
CONTENT
ssdeep
|
192:KPoMPOIZZzt5l5zfFNd5Y0u9CkUTJihnijprtA95iikyroAj:KPoyOIZZzt5l5T/D/kZnWxgI2Jj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ea6793d88a8f1c86 |
|
VISUAL
aHash
|
fce020a0f0d8ffff |
|
VISUAL
dHash
|
848c4a43a5b142b5 |
|
VISUAL
wHash
|
f4e02080f0d0fbff |
• Threat: Credential harvesting phishing targeting KuCoin users.
• Target: Users of KuCoin cryptocurrency exchange.
• Method: The phishing site presents a form to collect email/phone number, likely for credential theft.
• Exfil: Unknown, likely to a custom API or Telegram bot.
• Indicators: Free hosting on webflow.io, brand impersonation of KuCoin, input form for email/phone number.
• Risk: HIGH - Potential for immediate credential theft and account compromise.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain