EN ES PT
Back to Stats

Captura Visual

No screenshot available

Informações de Detecção

http://www.by.xfhkj.com/
Detected Brand
TikTok Wholesale
Country
International
Confidence
95%
HTTP Status
200
Report ID
e8b42130-e0d…
Analyzed
2025-12-20 15:12
Final URL (after redirects)
https://www.by.xfhkj.com/#/index

Hashes de Conteúdo (Similaridade HTML)

Used to detect similar phishing pages based on HTML content

Algorithm Hash Value
CONTENT TLSH
T12204FD71D695613B063788D4A4722F4FB2D7F31ECA978900A7FC43D96FEBCA1AA04485
CONTENT ssdeep
3072:jSOQLqPG8gkjbiStssJdPwTyd5ZuncsCcGT:jSOQLqPG8gkjbiStssJdPwTyd5Zuncss

Hashes Visuais (Similaridade de Captura)

Used to detect visually similar phishing pages based on screenshots

Algorithm Hash Value
VISUAL pHash
f6a518dd62a84376
VISUAL aHash
00ff77c3e6feff00
VISUAL dHash
c56cec8f4c48352d
VISUAL wHash
00ff6641e6fed700
VISUAL colorHash
06e00008000
VISUAL cropResistant
456cec8f4c482535,0000009393820080,010c686969697434,3535253d3d39edec

Análise de Código

Risk Score 70/100
Threat Level ALTO
🎣 Credential Harvester 🎣 OTP Stealer 🎣 Card Stealer 🎣 Banking 🎣 Personal Info

🔬 Threat Analysis Report

• Threat: Brand impersonation and potential data theft.
• Target: Users of TikTok Wholesale.
• Method: Fake website using the TikTok Wholesale brand to mislead users.
• Exfil: Unknown, potentially collecting user data or redirecting to malicious sites.
• Indicators: Domain name mismatch, unfamiliar domain extension, and generic website design.
• Risk: HIGH - The website is likely a phishing attempt.

📡 API Calls Detected

  • /public/userOnlineChatController!unread.action
  • /api/credit!beforereapply.action
  • /api/jscode!execute.action
  • /api/localuser!registerWithVerifcode.action
  • /api/credit!config.action
  • /api/credit!check.action
  • /api/localuser!get.action
  • /api/credit!histroy.action
  • post
  • /api/credit!apply.action
  • /api/localuser!registerNoVerifcode.action
  • /api/activity/lottery!getCurrentActivity.action
  • /api/category!tree.action
  • GET
  • api/syspara!getSyspara.action
  • /api/category!sellerTree.action
  • api/newOnlinechat!unread.action
  • /api/credit!pay.action
  • /api/credit!beforepay.action
  • /api/credit!bill.action
😰
"Nunca pensei que aconteceria comigo"
Isso dizem os 2,3 milhões de vítimas a cada ano. Não espere para ser uma estatística.