EN ES PT
Back to Stats

Captura Visual

Screenshot of aik.chase998.uk.cc

Informações de Detecção

http://aik.chase998.uk.cc
Detected Brand
Coupang, SSG, AliExpress, Gmarket, 11ST, Olive Young, Lotte ON
Country
South Korea
Confiança
100%
HTTP Status
200
Report ID
87a37f1a-79b…
Analyzed
2026-01-26 09:44
Final URL (after redirects)
http://aik.chase998.uk.cc/index/index/home.html

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T1D6921A29B54E5C62DF33C4C2A4E02D273499E3078A2A09E15BD905B59FD3CF0B989FB4
CONTENT ssdeep
96:YiryG1T0aP6kpxhHQEsW3wSUPVRUGrkE5K8VzQ/96DeLa1k+fyc2Cm/zSWtILOPo:Yi7TpAExrakOUz+yoVX/0/6

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
dcdd73f1e6260809
VISUAL aHash
e7fc181818180000
VISUAL dHash
0f32b3333332440e
VISUAL wHash
ffff3c3c3c3c0000
VISUAL colorHash
39600008200
VISUAL cropResistant
06066669c30f0684,0008bc98b9b7bc9d,0f00000000000008,a6a294554d3931c2,0f32b3333332440e

Análise de Código

Risk Score 68/100
Nível de Ameaça ALTO
⚠️ Phishing Confirmed
🎣 Credential Harvester 🎣 OTP Stealer

🔬 Threat Analysis Report

• Ameaça: Fraude de comissões de comércio eletrônico
• Alvo: Usuários na Coreia do Sul, com marcas de comércio eletrônico coreanas
• Método: Fraude que oferece comissões processando pedidos após um depósito inicial
• Exfil: Desconhecido, mas provavelmente coleta de informações pessoais/financeiras
• Indicators: Afirmações de comissões enganosas, domínio desconhecido, depósito obrigatório
• Risco: ALTO - Risco de perda financeira, roubo de dados pessoais

🔒 Obfuscation Detected

  • fromCharCode

📊 Detalhamento da Pontuação de Risco

Total Risk Score
100/100

Contributing Factors

Active Phishing Kit
Detected Credential Harvester and OTP Stealer kits with real-time form interception capabilities.
Brand Impersonation
Impersonates multiple high-profile e-commerce brands (Coupang, SSG, AliExpress, Gmarket, 11ST, Olive Young, Lotte ON) to deceive victims.
Obfuscation Techniques
Detected 2 obfuscation techniques in JavaScript files, complicating analysis and detection evasion.
Suspicious Claims
Promises commissions for processing orders and requires a minimum deposit of 100,000 KRW, indicating financial fraud.
Malicious JavaScript
Inclusion of JavaScript file (swiper-bundle.min.js) with potential obfuscation, totaling 0.14 MB in size.

🔬 Análise Integral de Ameaças

Tipo de Ameaça
Two-Factor Authentication Stealer
Alvo
Coupang, SSG, AliExpress, Gmarket, 11ST, Olive Young, Lotte ON users (South Korea)
Método de Ataque
Brand impersonation + credential harvesting forms + obfuscated JavaScript
Canal de Exfiltração
Unknown
Avaliação de Risco
HIGH - Automated credential harvesting with Unknown

⚠️ Indicators of Compromise

  • Kit types: Credential Harvester, OTP Stealer
  • 2 obfuscation techniques

🏢 Análise de Falsificação de Marca

Impersonated Brand
Coupang, SSG, AliExpress, Gmarket, 11ST, Olive Young, Lotte ON
Official Website
https://www.coupang.com, https://www.ssg.com, https://www.aliexpress.com, https://www.gmarket.co.kr, https://www.11st.co.kr, https://www.oliveyoung.co.kr, https://www.lotteon.com
Fake Service
Commission-based order processing

Fraudulent Claims

⚔️ Metodologia de Ataque

Primary Method: Credential Harvesting

The phishing kit captures user credentials through fake login forms mimicking e-commerce platforms. Submitted data is likely exfiltrated to an attacker-controlled server for account takeover or financial fraud.

Secondary Method: OTP Stealer

The kit includes functionality to intercept one-time passwords (OTPs) sent to victims, enabling attackers to bypass two-factor authentication and gain unauthorized access to accounts.

🌐 Indicadores de Compromisso de Infraestrutura

Domain Information

Domínio
aik.chase998.uk.cc
Registered
1997-10-13 04:00:00+00:00
Registrar
Gname.com Pte. Ltd.
Estado
Active (10332 days old)

🦠 Malicious Files

Main File
File Size

JavaScript file with potential obfuscation, associated with the phishing kit.

📊 Diagrama de Fluxo de Ataque

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LURE                          │
│    - Fake email/SMS with malicious link                  │
│    - Mimics Coupang, SSG, AliExpress, etc. branding     │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM LANDS ON FAKE SITE                             │
│    - Clone of legitimate e-commerce login page           │
│    - Requests user credentials                           │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT                                      │
│    - User enters username/password                       │
│    - Form appears identical to real site                 │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION                                     │
│    - Credentials sent via HTTP POST                      │
│    - Standard form submission to attacker server         │
└──────────────────────────────────────────────────────────┘
```

🔬 JavaScript Deep Analysis

Total Code Size
139,7 KB

🔗 API Endpoints Detected

Other
1

🔐 Obfuscation Detected

  • : Light

🤖 AI-Extracted Threat Intelligence

📊 Attack Flow

Here's a generic ASCII art attack flow diagram for the phishing attack:

```
┌──────────────────────────────────────────────────────────┐
│ 1. TARGET RECEIVES PHISHING LURE                          │
│    - Fake email/SMS with malicious link                  │
│    - Mimics Coupang, SSG, AliExpress, etc. branding     │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 2. VICTIM LANDS ON FAKE SITE                             │
│    - Clone of legitimate e-commerce login page           │
│    - Requests user credentials                           │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 3. CREDENTIAL INPUT                                      │
│    - User enters username/password                       │
│    - Form appears identical to real site                 │
└────────────────────┬─────────────────────────────────────┘
                     │
                     ▼
┌──────────────────────────────────────────────────────────┐
│ 4. DATA EXFILTRATION                                     │
│    - Credentials sent via HTTP POST                      │
│    - Standard form submission to attacker server         │
└──────────────────────────────────────────────────────────┘
```

🎯 Malicious Files Identified

😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.