Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CAA25635660052A703BB95C0F6607E2EB1D7F30FC506C656ABBD918A1FC3CB6BB22561 |
|
CONTENT
ssdeep
|
384:T+BxLNxLbFgF5FLFYF0CF6EFUFy+h89sF5:T+tAbxo0G6scy+h1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccccc6666663333 |
|
VISUAL
aHash
|
3018183018181018 |
|
VISUAL
dHash
|
2432302030302030 |
|
VISUAL
wHash
|
38183c381c183c3c |
|
VISUAL
colorHash
|
38003200040 |
|
VISUAL
cropResistant
|
2432302030302030 |
• Threat: Impersonation phishing
• Target: KuCoin users
• Method: Typosquatting, mimicking the KuCoin interface
• Exfil: wss://api., wss://webapi.16djht.com (potentially via websocket)
• Indicators: Domain typo, recent domain, obfuscated javascript.
• Risk: HIGH
The attacker registers a domain name that is similar to a legitimate domain, in this case kucoin.com, to lure users into providing sensitive information.
The presence of WebSocket URLs (wss://api., wss://webapi.16djht.com) suggests the possibility of real-time data exfiltration through websockets.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain