Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EBA25735660052A703BB95C0F6607E2EB1D7F30FC506C656ABBD918A1FC3CB6BB22561 |
|
CONTENT
ssdeep
|
384:T+1/C8/CCFgF5FLFYF0CF6EFUFy6OIyqF5:T+ZAbxo0G6scy6O0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccccc6666663333 |
|
VISUAL
aHash
|
3018183018181018 |
|
VISUAL
dHash
|
2432302030302030 |
|
VISUAL
wHash
|
38183c381c183c3c |
|
VISUAL
colorHash
|
38003200040 |
|
VISUAL
cropResistant
|
2432302030302030 |
• Threat: Phishing
• Target: KuCoin users
• Method: Impersonation of KuCoin website
• Exfil: wss://webapi.16djht.com, potentially other WebSocket URLs identified. Could be used to steal API keys, or other sensitive information.
• Indicators: Domain age, domain name, interface mimicry, obfuscation.
• Risk: High
The site likely attempts to trick users into entering their KuCoin credentials or API keys on a fake login page, which are then harvested by the attackers.
The site could redirect users to a malicious site or offer a malware download designed to steal financial information.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain