EN ES PT
Back to Stats

Visual Capture

No screenshot available

Detection Info

https://did.li/kiv6hs
Detected Brand
כביש 6
Country
Israel
Confidence
100%
HTTP Status
200
Report ID
f6826e6d-a4a…
Analyzed
2026-01-17 20:47
Final URL (after redirects)
https://vps122880.inmotionhosting.com/~cocojo6/ZK4RMP92TXLAQ9WD/

Content Hashes (HTML Similarity)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1E504ABF053D00D5A17B2B8D2DE23FE5A1FA2C6B1F91B2609E398566C5CE3EF0E942154
CONTENT ssdeep
1536:Q/qXecbH0C/YJMQYEHBXOgit7iZePEcPXSWxcfy+bH2+96LMQmYHVxggit7wZkP8:/XB4G0zTw6+3J6+G+HQqaG7h

Visual Hashes (Screenshot Similarity)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
b131c69b9bce6431
VISUAL aHash
ffc3c3dfcfd3f3ff
VISUAL dHash
609696131b17279e
VISUAL wHash
ffc381898981dbc3
VISUAL colorHash
07001000180
VISUAL cropResistant
609696131b17279e,01a209b606b0bc83

Code Analysis

Risk Score 85/100
Threat Level BAJO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Information gathering.
• Target: Kvish 6 toll road users in Israel.
• Method: Payment form on the website.
• Exfil: Unknown.
• Indicators: URL shortening service, kvish6 logo.
• Risk: LOW - Data collection from website.

🔐 Credential Harvesting Forms

🔒 Obfuscation Detected

  • atob
  • eval
  • fromCharCode
  • unescape
  • hex_escape
  • unicode_escape
  • base64_strings

🎯 Kit Endpoints

  • https://service.kvish6.co.il/#/website/customer-area/login

📡 API Calls Detected

  • GET
  • https://www.google.com/ccm/geo
  • POST

📤 Form Action Targets

  • https://translate.googleapis.com/translate_voting?client=te_lib
  • step1.php
😰
"I Never Thought It Would Happen to Me"
That's what 2.3 million victims say every year. Don't wait to become a statistic.