Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EBA25735660052A703BB95C0F6607E2EB1D7F30FC506C656ABBD918A1FC3CB6BB22561 |
|
CONTENT
ssdeep
|
384:T+1/C8/CCFgF5FLFYF0CF6EFUFy6OIyqF5:T+ZAbxo0G6scy6O0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cccccc6666663333 |
|
VISUAL
aHash
|
3018183018181018 |
|
VISUAL
dHash
|
2432302030302030 |
|
VISUAL
wHash
|
38183c381c183c3c |
|
VISUAL
colorHash
|
38003200040 |
|
VISUAL
cropResistant
|
2432302030302030 |
• Amenaza: Phishing
• Objetivo: Usuarios de KuCoin
• Método: Imitación del sitio web de KuCoin
• Exfil: wss://webapi.16djht.com, potencialmente otras URLs de WebSocket identificadas. Podría usarse para robar claves API u otra información confidencial.
• Indicadores: Edad del dominio, nombre del dominio, imitación de la interfaz, ofuscación.
• Riesgo: Alto
The site likely attempts to trick users into entering their KuCoin credentials or API keys on a fake login page, which are then harvested by the attackers.
The site could redirect users to a malicious site or offer a malware download designed to steal financial information.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain